Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

2286 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.1)0.53%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (7.5)0.97%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.
AnalizadaMedia (6.5)1.1%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.
AnalizadaCrítica (9.8)0.97%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (6.1)0.55%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
Pendiente de análisisAlta (7.8)0.36%—SAP Netweaver Business ClientAI8/9/20269/9/2026
SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content. When the application is next launched, the crafted content is…
AnalizadaAlta (8.7)0.38%—Emxtecnologia Gestao X Business Suite4/9/202617/9/2026
A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earlier. The vulnerability is caused by insufficient validation and sanitization of the mensagem parameter in the /Configuracao/Imagens.aspx endpoint, allowing an authenticated attacker to inject arbitrary…
AnalizadaAlta (8.7)0.38%—Emxtecnologia Gestao X Business Suite4/9/202617/9/2026
EMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Help Chat functionality. Improper neutralization of user-controlled input during web page generation allows authenticated attackers to execute arbitrary JavaScript in the context of other authenticated users,…
AplazadaMedia (6.5)0.27%—Business DirectoryAI3/9/20267/9/2026
Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions.
AplazadaMedia (6.5)0.33%—Business DirectoryAI3/9/20265/9/2026
Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions.
AplazadaAlta (8.7)0.43%—Cmsjunkie J-business DirectoryAI19/8/202626/8/2026
Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-BusinessDirectory < 6.2.3 - Pagination values were not strictly typed. Array/non-numeric values (for example limitstart[]) could trigger PHP type errors in arithmetic, and limit was not validated before use in list queries.
AplazadaMedia (5.1)0.44%—JoomlaAICmsjunkie J-businessdirectoryAI19/8/202626/8/2026
Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - companyName from the request was written unescaped into an XML attribute.
AplazadaCrítica (9.3)0.39%—Cmsjunkie J-businessdirectoryAI19/8/202626/8/2026
Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Search keywords and ORDER BY were concatenated into SQL. 6.2.3 quotes keywords and allow-lists the sort clause.
AplazadaAlta (7.5)0.42%—Cmsjunkie J-businessdirectoryAIJoomlaAI19/8/202626/8/2026
Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so mail could be sent to an arbitrary address.
AplazadaMedia (4.6)0.21%—Cmsjunkie J-business DirectoryAI19/8/202626/8/2026
Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3 - Tokens were missing on many AJAX/state-changing tasks: contact/quote forms, cart, bookmarks, uploads, messages, AI text generation, and several administrator actions (app install, demo-data wipe, cache/statistics archive,…
AplazadaMedia (6.9)0.41%—Cmsjunkie J-business DirectoryAI19/8/202626/8/2026
Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3
AplazadaMedia (6.9)0.41%—Cmsjunkie J-businessdirectoryAI19/8/202626/8/2026
Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attacker-supplied company and user IDs, including for listings that already had an owner. 6.2.3 binds the action to the authenticated user and only allows unowned listings.
AplazadaCrítica (10)0.43%—JoomlaAICmsjunkie J-businessdirectoryAI19/8/202626/8/2026
Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path containment, and used a weak extension check. CSRF token was also…
AnalizadaAlta (8)0.38%—Oracle Business Intelligence18/8/202624/8/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business…
AnalizadaAlta (7.5)0.41%—Oracle Business Intelligence18/8/202624/8/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business…
AnalizadaAlta (7.2)0.49%—Oracle Business Intelligence18/8/202624/8/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web Answers). The supported version that is affected is 26.01.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business…
AnalizadaAlta (7)0.13%—Oracle Business Intelligence18/8/202624/8/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence…
AnalizadaAlta (7.8)0.16%—Oracle Business Intelligence18/8/202624/8/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence…
AnalizadaAlta (8.2)0.29%—Oracle Business Intelligence18/8/202624/8/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to…
AnalizadaAlta (8.3)0.39%—Oracle Business Intelligence18/8/202624/8/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business…
Orbitaley — Vulnerabilidades