Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

1234 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.4)0.27%💥 PoCSAP Netweaver Application Server JavaAI11/2/202517/6/2026
SAP NetWeaver Application Server Java does not sufficiently handle user input, resulting in a stored cross-site scripting vulnerability. The application allows attackers with basic user privileges to store a Javascript payload on the server, which could be later executed in the victim's web browser. With this the…
AnalizadaAlta (7.8)0.41%—Parallels Remote Application ServerParallels5/2/202517/6/2026
Parallels Desktop Technical Data Reporter Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order…
AplazadaCrítica (9.9)0.70%—SAP Netweaver Application Server FOR AbapAISAP Abap PlatformAI14/1/202517/6/2026
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate access to the system by exploiting improper authentication checks, resulting in privilege escalation. On successful exploitation, this can result in potential security concerns. This results in a high…
AplazadaMedia (4.3)0.27%—SAP Netweaver Application Server AbapAI14/1/202517/6/2026
An obsolete functionality in SAP NetWeaver Application Server ABAP did not perform necessary authorization checks. Because of this, an authenticated attacker could obtain information that would otherwise be restricted. It has no impact on integrity or availability on the application.
AplazadaMedia (6.3)0.26%—SAP Netweaver Application Server JavaAI14/1/202517/6/2026
Due to a missing authorization check on service endpoints in the SAP NetWeaver Application Server Java, an attacker with standard user role can create JCo connection entries, which are used for remote function calls from or to the application server. This could lead to low impact on confidentiality, integrity, and…
AplazadaMedia (6)0.18%—SAP Netweaver Application Server AbapAISAP GUI FOR HtmlAI14/1/202517/6/2026
Applications based on SAP GUI for HTML in SAP NetWeaver Application Server ABAP store user input in the local browser storage to improve usability. An attacker with administrative privileges or access to the victim�s user directory on the Operating System level would be able to read this data. Depending on the user…
AplazadaAlta (8.5)0.60%—SAP Netweaver Application Server AbapAI10/12/202417/6/2026
In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, which can be used to expose credentials for a remote service. These credentials can then be further exploited to completely compromise the remote…
AplazadaMedia (4.3)0.27%—SAP Netweaver Application Server FOR AbapAISAP Abap PlatformAI10/12/202417/6/2026
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to gain higher access levels than they should have by exploiting improper authorization checks, resulting in privilege escalation. While authorizations for import and export are distinguished, a single authorization is applied…
AplazadaMedia (4.3)0.38%—SAP Netweaver Application Server AbapAISAP WEB DispatcherAISAP GUI FOR HtmlAI12/11/202417/6/2026
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the server, which otherwise would be restricted.This attack is possible only if a Web Dispatcher or some sort of Proxy Server is in use and the file in question was previously opened or downloaded in an…
AplazadaMedia (5.3)3.5%—SAP Netweaver Application Server FOR AbapAISAP Abap PlatformAI12/11/202417/6/2026
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a maliciously crafted http request which could cause a null pointer dereference in the kernel. This dereference will result in the system crashing and rebooting, causing the system to be temporarily unavailable.…
AnalizadaMedia (4.8)0.23%—IBM Websphere Application Server11/11/202417/6/2026
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AnalizadaMedia (5.5)0.44%—IBM Websphere Application Server4/11/202417/6/2026
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.
AnalizadaMedia (5.5)0.44%—IBM Websphere Application Server16/10/202417/6/2026
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.
AnalizadaMedia (4.8)0.25%—IBM Websphere Application Server16/10/202417/6/2026
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AnalizadaAlta (7.5)0.56%—IBM Websphere Application Server15/10/202417/6/2026
IBM WebSphere Application Server 8.5 is vulnerable to a denial of service, under certain configurations, caused by an unexpected specially crafted request. A remote attacker could exploit this vulnerability to cause an error resulting in a denial of service.
AnalizadaMedia (4.8)0.25%—IBM Websphere Application Server30/9/202417/6/2026
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AplazadaMedia (6.1)0.27%—SAP Netweaver Application Server FOR AbapAI10/9/202417/6/2026
Due to insufficient input validation, CRM Blueprint Application Builder Panel of SAP NetWeaver Application Server for ABAP allows an unauthenticated attacker to craft a URL link which could embed a malicious JavaScript. When a victim clicks on this link, the script will be executed in the victim's browser giving the…
AnalizadaBaja (2.7)0.29%—SAP Netweaver Application Server Abap10/9/202417/6/2026
Due to missing authorization check, SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker logged in as a developer to read objects contained in a package. This causes an impact on confidentiality, as this attacker would otherwise not have access to view these objects.
AnalizadaBaja (2.7)0.26%—SAP Netweaver Application Server Abap10/9/202417/6/2026
SAP NetWeaver Application Server for ABAP and ABAP Platform allow users with high privileges to execute a program that reveals data over the network. This results in a minimal impact on confidentiality of the application.
AnalizadaAlta (7.5)0.26%—IBM Websphere Application Server14/8/202417/6/2026
IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.8 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued by a trusted authority to obtain sensitive information. IBM X-Force ID: 274713.
AnalizadaMedia (5.9)0.27%—IBM Websphere Application Server14/8/202417/6/2026
IBM WebSphere Application Server 8.5 and 9.0 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued by a trusted authority to obtain sensitive information. IBM X-Force ID: 274714.
AnalizadaMedia (4.3)0.26%—SAP Netweaver Application Server Abap13/8/202417/6/2026
Due to missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform, an authenticated attacker could call an underlying transaction, which leads to disclosure of user related information. There is no impact on integrity or availability.
AnalizadaMedia (5.4)0.32%—SAP Netweaver Application Server Abap13/8/202417/6/2026
—
ModificadaAlta (8.7)0.77%—Siemens Omnivise T3000 Application Server2/8/202417/6/2026
A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions). The affected system exposes the port of an internal application on the public network interface allowing an attacker to circumvent authentication…
ModificadaMedia (6.9)11%—Siemens Omnivise T3000 Application Server2/8/202417/6/2026
A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions). Affected devices allow authenticated users to export diagnostics data. The corresponding API endpoint is susceptible to path traversal and could…
Orbitaley — Vulnerabilidades