Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2637▼ 209 respecto a la semana anterior
Críticas / altas1378▲ 149 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.34%—Comerzzia Backoffice Sales OrchestratorAI20/5/202517/6/2026
SQL injection vulnerability in Comerzzia Backoffice: Sales Orchestrator 3.0.15. This vulnerability allows an attacker to retrieve, create, update and delete databases via the ‘uidActivity’, ‘codCompany’ and ‘uidInstance’ parameters of the ‘/comerzzia/login’ endpoint.
AnalizadaMedia (5.4)0.26%—SAP Commerce Backoffice8/10/202417/6/2026
SAP Commerce Backoffice does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause limited impact on confidentiality and integrity of the application.
AnalizadaMedia (5.4)0.24%—SAP Commerce Backoffice13/8/202417/6/2026
SAP Commerce Backoffice does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability causing low impact on confidentiality and integrity of the application.
ModificadaMedia (4.3)1.4%—Comersus Open Technologies Comersus Backoffice LiteComersus Open Technologies Comersus Backoffice Plus1/11/200516/6/2026
Cross-site scripting (XSS) vulnerability in Comersus BackOffice allows remote attackers to inject arbitrary web script or HTML via the error parameter to comersus_backoffice_supportError.asp. NOTE: the comersus_backoffice_message.asp/message vector is already covered by CVE-2005-2191 item 2.
ModificadaMedia (4.3)3.5%—Comersus Open Technologies Comersus Backoffice Plus23/10/200516/6/2026
Cross-site scripting (XSS) vulnerability in comersus_backoffice_searchItemForm.asp in Comersus BackOffice Plus allows remote attackers to inject arbitrary web script or HTML via the (1) forwardTo1, (2) forwardTo2, (3) nameFT1, or (4) nameFT2 parameters.
ModificadaMedia (4.3)1.2%—Comersus Open Technologies Comersus Backoffice Lite2/5/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in (1) comersus_supportError.asp or (2) comersus_backofficelite_supportError.asp in BackOffice Lite 6.0 and 6.01 allow remote attackers to inject arbitrary web script or HTML via the error parameter.
ModificadaAlta (7.5)1.6%—Comersus Open Technologies Comersus Backoffice Lite2/5/200516/6/2026
comersus_backoffice_install10.asp in BackOffice Lite 6.0 and 6.01 allows remote attackers to bypass authentication and gain privileges via a direct request to the program.
ModificadaAlta (7.5)1.3%—Comersus Open Technologies Comersus Backoffice Lite2/5/200516/6/2026
SQL injection vulnerability in default.asp in BackOffice Lite 6.0 and 6.01 allows remote attackers to execute arbitrary SQL commands via the referer field in the HTTP header.
ModificadaAlta (10)32%—Microsoft Backoffice12/8/200216/6/2026
Microsoft BackOffice 4.0 and 4.5, when configured to be accessible by other systems, allows remote attackers to bypass authentication and access the administrative ASP pages via an HTTP request with an authorization type (auth_type) that is not blank.
ModificadaAlta (7.5)5.8%—Microsoft Backoffice Resource KIT22/2/199916/6/2026
Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting.
ModificadaBaja (2.1)4.2%—Microsoft Windows 2000Microsoft Windows NTMicrosoft Backoffice12/2/199916/6/2026
The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.