Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.83%—Unit4 Enterprise Resource Planning19/7/202217/6/2026
Unit4 ERP through 7.9 allows XXE via ExecuteServerProcessAsynchronously.
ModificadaAlta (7.5)1.0%—Dalmark Systeam Enterprise Resource Planning21/12/202117/6/2026
Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to Incorrect Access Control. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts. A broken access control vulnerability has been found while…
ModificadaMedia (5.3)0.79%—Dalmark Systeam Enterprise Resource Planning21/12/202117/6/2026
Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts. This issue occurs during the identification of the correct tenant for…
ModificadaMedia (5.3)0.79%—Dalmark Systeam Enterprise Resource Planning21/12/202117/6/2026
Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts. This issue occurs during the password recovery procedure for a given…
ModificadaAlta (8.8)1.0%—Dalmark Systeam Enterprise Resource Planning21/12/202117/6/2026
Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to Insecure design on report build via SQL query. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts. The bi report module exposes direct SQL…
ModificadaMedia (5.4)0.59%—Junhetec Enterprise Resource Planning Point OF Sale System7/5/202117/6/2026
Special characters of ERP POS news page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks, additionally access and manipulate customer’s information.
ModificadaMedia (5.4)0.59%—Junhetec Enterprise Resource Planning Point OF Sale System7/5/202117/6/2026
Special characters of ERP POS customer profile page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks, additionally access and manipulate customer’s information.
ModificadaMedia (6.5)0.74%—Web-school Enterprise Resource Planning8/4/202117/6/2026
Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a voucher payment request through module/accounting/voucher/create. The application fails to validate the CSRF token for a POST request using admin privilege.
ModificadaMedia (6.1)0.95%—Web-school Enterprise Resource Planning8/4/202117/6/2026
A blind XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in event name and description fields. An attacker can inject a JavaScript code that will be stored in the page. If any visitor sees the event, then the payload will be executed and sends the victim's information to the attacker website.
ModificadaMedia (6.5)0.74%—Web-school Enterprise Resource Planning8/4/202117/6/2026
Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a student_leave_application request through module/core/studentleaveapplication/create. The application fails to validate the CSRF token for a POST request using Guardian privilege.
ModificadaMedia (5.4)0.73%—Web-school Enterprise Resource Planning8/4/202117/6/2026
A stored XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in the event name and description fields. An attack can inject a JavaScript code that will be stored in the page. If any visitor sees the events, then the payload will be executed.
ModificadaAlta (7.5)1.3%—SAP Enterprise Resource Planning22/1/201517/6/2026
The Dealer Portal in SAP ERP does not properly restrict access, which allows remote attackers to obtain sensitive information, gain privileges, and possibly have other unspecified impact via unknown vectors, aka SAP Note 2000401. NOTE: the provenance of this information is unknown; the details are obtained solely from…