Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

431 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)0.75%—Sage X322/6/20239/7/2026
Sage X3 version 12.14.0.50-0 is vulnerable to CSV Injection.
ModificadaMedia (4.3)0.40%—Sage 30016/5/202317/6/2026
Versions of Sage 300 through 2022 implement role-based access controls that are only enforced client-side. Low-privileged Sage users, particularly those on a workstation setup in the "Windows Peer-to-Peer Network" or "Client Server Network" Sage 300 configurations, could recover the SQL connection strings being used…
ModificadaMedia (4.8)0.39%—Messagebird Sparkpost15/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SparkPost plugin <= 3.2.5 versions.
ModificadaAlta (7.8)0.22%—Intel System Usage Report10/5/202317/6/2026
Improper access control in the Intel(R) SUR software before version 2.4.8989 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaCrítica (9.8)0.63%—Sage 30028/4/202317/6/2026
Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection strings stored in ISAM database files in the shared data directory. This issue could allow attackers to decrypt user passwords and SQL connection strings.
ModificadaAlta (7.5)0.58%—Sage 30028/4/202317/6/2026
The optional Web Screens feature for Sage 300 through version 2022 uses a hard-coded 40-byte blowfish key ("PASS_KEY") to encrypt and decrypt the database connection string for the PORTAL database found in the "dbconfig.xml". This issue could allow attackers to obtain access to the SQL database.
ModificadaAlta (7.5)0.53%—Sage 30028/4/202317/6/2026
The optional Global Search feature for Sage 300 through version 2022 uses a set of hard-coded credentials for the accompanying Apache Solr instance. This issue could allow attackers to login to the Solr dashboard with admin privileges and access sensitive information.
ModificadaCrítica (9.8)0.68%—Sage 30028/4/202317/6/2026
The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish key ("LandlordPassKey") to encrypt and decrypt secrets stored in configuration files and in database tables.
ModificadaAlta (7.8)0.26%—Sage 30028/4/20239/7/2026
On versions of Sage 300 2017 - 2022 (6.4.x - 6.9.x) which are setup in a "Windows Peer-to-Peer Network" or "Client Server Network" configuration, a low-privileged Sage 300 workstation user could abuse their access to the "SharedData" folder on the connected Sage 300 server to view and/or modify the credentials…
ModificadaMedia (6.1)0.41%—Rarathemes Vryasage Marketing Performance23/4/202317/6/2026
Reflected Cross-Site Scripting (XSS) vulnerability in VryaSage Marketing Performance plugin <= 2.0.0 versions.
ModificadaMedia (5.5)0.24%—Sagemath Flintqs6/4/202317/6/2026
SageMath FlintQS 1.0 relies on pathnames under TMPDIR (typically world-writable), which (for example) allows a local user to overwrite files with the privileges of a different user (who is running FlintQS).
ModificadaAlta (7.8)0.17%—Intel System Usage Report16/2/202317/6/2026
Improper access control in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaCrítica (9.8)0.65%—Intel System Usage Report16/2/202317/6/2026
Improper input validation in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
ModificadaAlta (7.8)0.18%—Intel System Usage Report16/2/202317/6/2026
Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.23%—Intel System Usage Report16/2/202317/6/2026
Improper input validation in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.2)0.44%—Intel System Usage Report16/2/202317/6/2026
Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow a privileged user to potentially enable escalation of privilege via network access.
ModificadaMedia (5.5)0.18%—Intel System Usage Report16/2/202317/6/2026
Improper access control in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaAlta (7.5)0.61%—Intel System Usage Report16/2/202317/6/2026
Improper conditions check in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potentially enable denial of service via network access.
ModificadaCrítica (9.8)0.57%—Intel System Usage Report16/2/202317/6/2026
Improper access control in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
ModificadaAlta (8.8)0.72%—Forget Heart Message BOX Project Forget Heart Message BOX1/2/202317/6/2026
Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /cha.php.
ModificadaCrítica (9.8)0.74%—Forget Heart Message BOX Project Forget Heart Message BOX1/2/202317/6/2026
Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/loginpost.php.
ModificadaAlta (7.5)1.1%—Sage FRP 100027/1/202317/6/2026
A path traversal vulnerability exists in Sage FRP 1000 before November 2019. This allows remote unauthenticated attackers to access files outside of the web tree via a crafted URL.
ModificadaAlta (8.8)12%—Sage XRT Business Exchange1/1/202317/6/2026
Multiple SQL injections in Sage XRT Business Exchange 12.4.302 allow an authenticated attacker to inject malicious data in SQL queries: Add Currencies, Payment Order, and Transfer History.
ModificadaMedia (5.4)0.40%—Sage XRT Business Exchange1/1/202317/6/2026
Multiple XSS issues were discovered in Sage XRT Business Exchange 12.4.302 that allow an attacker to execute JavaScript code in the context of other users' browsers. The attacker needs to be authenticated to reach the vulnerable features. An issue is present in the Filters and Display model features (OnlineBanking >…
ModificadaCrítica (9)0.76%—Sage Enterprise Intelligence1/1/202317/6/2026
Multiple XSS issues were discovered in Sage Enterprise Intelligence 2021 R1.1 that allow an attacker to execute JavaScript code in the context of users' browsers. The attacker needs to be authenticated to reach the vulnerable features. An issue is present in the Notify Users About Modification menu and the…
Orbitaley — Vulnerabilidades