Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
203 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4) | 1.2% | — | SAP Hana | 29/5/2015 | 17/6/2026 | SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote authenticated users to read arbitrary files via an IMPORT FROM SQL statement, aka SAP Security Note 2109565. | |
| Modificada | Media (4) | 1.2% | — | SAP Hana | 29/5/2015 | 17/6/2026 | The grant.xsfunc application in testApps/grantAccess/ in the XS Engine in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote authenticated users to spoof log entries via a crafted request, aka SAP Security Note 2109818. | |
| Modificada | Media (4.3) | 1.9% | — | SAP Hana | 27/2/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in SAP HANA 73 (1.00.73.00.389160) and HANA Developer Edition 80 (1.00.80.00.391861) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) ide/core/plugins/editor/templates/trace/hanaTraceDetailService.xsjs or (2)… | |
| Modificada | Alta (10) | 2.2% | — | SAP Hana Extended Application Services | 22/1/2015 | 17/6/2026 | The Extended Application Services (XS) in SAP HANA allows remote attackers to inject arbitrary ABAP code via unspecified vectors, aka SAP Note 2098906. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 0.93% | — | SAP Hana Web-based Development Workbench | 6/11/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in SAP HANA Web-based Development Workbench allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.3% | — | SAP Hana | 4/11/2014 | 17/6/2026 | SQL injection vulnerability in metadata.xsjs in SAP HANA 1.00.60.379371 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.3% | — | SAP CommoncryptolibSapcryptolibSapseculibSAP Hana+1 | 4/11/2014 | 17/6/2026 | SAPCRYPTOLIB before 5.555.38, SAPSECULIB, and CommonCryptoLib before 8.4.30, as used in SAP NetWeaver AS for ABAP and SAP HANA, allows remote attackers to spoof Digital Signature Algorithm (DSA) signatures via unspecified vectors. | |
| Modificada | Media (5.4) | 0.27% | — | Magzter Dhanam | 19/10/2014 | 17/6/2026 | The Dhanam (aka com.magzter.dhanam) application 3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 2.2% | — | SAP Hana | 16/10/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in SAP HANA Developer Edition Revision 70 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) epm/admin/DataGen.xsjs or (2) epm/services/multiply.xsjs in the democontent. | |
| Modificada | Media (6) | 2.1% | — | SAP Hana | 16/10/2014 | 17/6/2026 | Eval injection in ide/core/base/server/net.xsjs in the Developer Workbench in SAP HANA allows remote attackers to execute arbitrary XSJX code via unspecified vectors. | |
| Modificada | Media (5.4) | 0.27% | — | Hanabank | 9/9/2014 | 17/6/2026 | The hananbank (aka com.hanabank.ebk.channel.android.hananbank) application 4.06 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5) | 2.8% | — | SAP Hana Extended Application Services | 31/7/2014 | 17/6/2026 | SAP HANA Extend Application Services (XS) allows remote attackers to bypass access restrictions via a request to a private IU5 SDK application that was once public. | |
| Modificada | Media (4.3) | 2.5% | — | SAP Hana | 31/7/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the XS Administration Tools in SAP HANA allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (2.9) | 1.5% | — | SAP Hana Extended Application Services | 31/7/2014 | 17/6/2026 | SAP HANA Extend Application Services (XS) does not encrypt transmissions for applications that enable form based authentication using SSL, which allows remote attackers to obtain credentials and other sensitive information by sniffing the network. | |
| Modificada | Media (5) | 1.5% | — | SAP Hana | 10/4/2014 | 17/6/2026 | The HANA ICM process in SAP HANA allows remote attackers to obtain the platform version, host name, instance number, and possibly other sensitive information via a malformed HTTP GET request. | |
| Modificada | Alta (9.3) | 3.8% | — | Justsystems HanakoJustsystems Hanako PoliceJustsystems Hanako Police3Justsystems Ichitaro+1 | 1/3/2013 | 16/6/2026 | Unspecified vulnerability in JustSystems Ichitaro 2006 and 2007, Ichitaro Government 2006 and 2007, Ichitaro Portable with oreplug, Hanako 2006 through 2013, Hanako Police, Hanako Police 3, and Hanako Police 2010 allows remote attackers to execute arbitrary code via a crafted file. | |
| Modificada | Media (6.8) | 0.76% | — | Hulihanapplications Amethyst | 14/2/2012 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in admin/update_user in Hulihan Amethyst 0.1.5, and possibly earlier, allow remote attackers to hijack the authentication of administrators for requests that (1) change the administrative password or (2) change the site's configuration. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Hulihanapplications Hulihan BXR | 9/10/2011 | 16/6/2026 | SQL injection vulnerability in folder/list in Hulihan BXR 0.6.8 allows remote attackers to execute arbitrary SQL commands via the order_by parameter. | |
| Modificada | Media (6.8) | 1.4% | 💥 Exploit | Hulihanapplications Diamondlist | 16/8/2010 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in user/main/update_user in DiamondList 0.1.6, and possibly earlier, allow remote attackers to hijack the authentication of administrators for requests that (1) change the administrative password or (2) change the site's configuration. | |
| Modificada | Media (4.3) | 2.6% | 💥 Exploit | Hulihanapplications Diamondlist | 16/8/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in DiamondList 0.1.6, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) category[description] parameter to user/main/update_category, which is not properly handled by _app/views/categories/index.html.erb; and the (2)… | |
| Modificada | Media (6.4) | 1.5% | — | Sahanafoundation Sahana | 31/3/2010 | 16/6/2026 | Sahana disaster management system 0.6.2.2, and possibly other versions, allows remote attackers to bypass intended access restrictions and disable administrator authentication via a direct request to stream.php in an acl_enable_acl action to the admin module. | |
| Modificada | Alta (7.5) | 8.2% | 💥 Exploit | Sahana | 26/10/2009 | 16/6/2026 | Directory traversal vulnerability in www/index.php in Sahana 0.6.2.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod parameter. | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Auracms Modul Forum Sederhana | 7/8/2007 | 16/6/2026 | SQL injection vulnerability in komentar.php in the Forum Module for auraCMS (Modul Forum Sederhana) allows remote attackers to execute arbitrary SQL commands via the id parameter to the default URI. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Berthanas Ziyaretci Defteri | 1/8/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in yonetici.asp in Berthanas Ziyaretci Defteri 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) user and (2) Pass fields. | |
| Modificada | Media (6.8) | 3.1% | — | Justsystem HanakoJustsystem Hanako ViewerJustsystem IchitaroJustsystem Ichitaro Lite2+2 | 10/12/2006 | 16/6/2026 | Buffer overflow in JustSystems Hanako 2004 through 2006, Hanako viewer 1.x, Ichitaro 2004, Ichitaro 2005, Ichitaro Lite2, Ichitaro viewer 4.x, and Sanshiro 2005 allows remote attackers to execute arbitrary code via the (1) Keyword and (2) Title fields, related to string length fields. |