Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

1234 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.22%—Desktopalert Pingalert Application Server24/11/202517/6/2026
A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There are Hard-coded configuration values.
AnalizadaAlta (7.5)0.28%—Desktopalert Pingalert Application Server24/11/202517/6/2026
An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to disclose user hashes.
AplazadaAlta (7.2)0.16%—IBM Application ServerAI15/11/202517/6/2026
The vulnerability, if exploited, could allow an authenticated miscreant (with privilege of "aaConfigTools") to tamper with App Objects' help files and persist a cross-site scripting (XSS) injection that when executed by a victim user, can result in horizontal or vertical escalation of privileges. The vulnerability can…
AnalizadaMedia (4.3)0.22%—Desktopalert Pingalert Application Server14/11/202517/6/2026
A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Technical Information to be Disclosed through stack trace.
AnalizadaMedia (4.3)0.20%—Desktopalert Pingalert Application Server14/11/202517/6/2026
An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows remote access to content despite lack of the correct permission through a Broken Authorization Schema.
AnalizadaBaja (3.8)0.19%—Desktopalert Pingalert Application Server14/11/202517/6/2026
A Server-side Request Forgery vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Probing of internal infrastructure.
AnalizadaBaja (3.7)0.28%—Desktopalert Pingalert Application Server14/11/202517/6/2026
An issue was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows remote Path Traversal for loading arbitrary external content.
AnalizadaMedia (6.5)0.17%—Desktopalert Pingalert Application Server14/11/202517/6/2026
A Stored Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to hijack user’s browser, capturing sensitive information.
AnalizadaAlta (7.6)0.25%—Desktopalert Pingalert Application Server14/11/202517/6/2026
A Reflected Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to hijack user’s browser, capturing sensitive information.
AnalizadaAlta (7.5)0.30%—Desktopalert Pingalert Application Server14/11/202517/6/2026
An issue was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. Sensitive Information is exposed to an Unauthorized Actor.
AnalizadaCrítica (9.6)0.26%—Desktopalert Pingalert Application Server14/11/202517/6/2026
An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 exploitable remotely for Escalation of Privileges.
AnalizadaBaja (3.3)0.09%—Desktopalert Pingalert Application Server14/11/202517/6/2026
A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There is Exposure of Sensitive Information because of Incompatible Policies.
AnalizadaMedia (4.1)0.09%—Desktopalert Pingalert Application Server14/11/202517/6/2026
A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There is a Broken or Risky Cryptographic Algorithm.
AnalizadaCrítica (10)0.31%—Desktopalert Pingalert Application Server14/11/202517/6/2026
An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 exploitable remotely for Escalation of Privileges.
AplazadaMedia (5.3)0.46%—SAP Netweaver Application Server JavaAI11/11/202517/6/2026
Due to an Information Disclosure vulnerability in SAP NetWeaver Application Server Java, internal metadata files could be accessed via manipulated URLs. An unauthenticated attacker could exploit this vulnerability by inserting arbitrary path components in the request, allowing unauthorized access to sensitive…
AplazadaBaja (2.7)0.25%—SAP Netweaver Application Server FOR AbapAISAP Migration WorkbenchAISAP DX WorkbenchAI11/11/202517/6/2026
Migration Workbench (DX Workbench) in SAP NetWeaver Application Server for ABAP fails to trigger a malware scan when an attacker with administrative privileges uploads files to the application server. An attacker could leverage this and upload a malicious file into the system. This results in a low impact on the…
AplazadaMedia (4.3)0.23%—SAP Netweaver Application Server AbapAI11/11/202517/6/2026
Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with basic privileges could execute a specific function module in ABAP to retrieve restricted technical information from the system. This disclosure of environment details of the system could further assist…
AplazadaAlta (7.5)0.36%—Bessystem BES Application ServerAI28/10/20255/7/2026
An issue was discovered in BESSystem BES Application Server thru 9.5.x allowing unauthorized attackers to gain sensitive information via the "pre-resource" option in bes-web.xml.
AplazadaMedia (5.4)0.16%—SAP Netweaver Application Server FOR AbapAI14/10/202517/6/2026
Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP, an authenticated attacker could initiate transactions directly via the session manager, bypassing the first transaction screen and the associated authorization check. This vulnerability could allow the attacker to…
AplazadaMedia (5.4)0.23%—SAP Application Server FOR AbapAI14/10/202517/6/2026
SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript payloads which could be executed in victim user's browser when accessing the affected functionality of BAPI explorer. This has low impact on confidentiality and integrity with no impact on availability of the application.
AnalizadaMedia (4.9)0.32%—IBM Websphere Application Server29/9/202517/6/2026
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A privileged user could exploit this vulnerability to cause the server to consume memory resources.
AplazadaCrítica (9.3)0.67%—Generalbytes Crypto Application ServerAI19/9/202517/6/2026
General Bytes Crypto Application Server (CAS) beginning with version 20201208 prior to 20220531.38 (backport) and 20220725.22 (mainline) contains an authentication bypass in the admin web interface. An unauthenticated attacker could invoke the same URL used by the product's default-installation / first-admin creation…
AnalizadaMedia (5.3)0.30%—SAP Netweaver Application Server Java9/9/202517/6/2026
SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files within the web application.Upon successfully exploitation, an unauthenticated attacker could access these files to gather additional sensitive information about the system.This…
ModificadaAlta (7.5)0.45%—IBM Websphere Application Server14/8/202517/6/2026
IBM WebSphere Application Server Liberty 18.0.0.2 through 25.0.0.8 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
AnalizadaAlta (7.5)0.27%—IBM Websphere Application Server14/8/202517/6/2026
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS connections.
Orbitaley — Vulnerabilidades