Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.34% | — | Comerzzia Backoffice Sales OrchestratorAI | 20/5/2025 | 17/6/2026 | SQL injection vulnerability in Comerzzia Backoffice: Sales Orchestrator 3.0.15. This vulnerability allows an attacker to retrieve, create, update and delete databases via the ‘uidActivity’, ‘codCompany’ and ‘uidInstance’ parameters of the ‘/comerzzia/login’ endpoint. | |
| Analizada | Media (5.4) | 0.26% | — | SAP Commerce Backoffice | 8/10/2024 | 17/6/2026 | SAP Commerce Backoffice does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause limited impact on confidentiality and integrity of the application. | |
| Analizada | Media (5.4) | 0.24% | — | SAP Commerce Backoffice | 13/8/2024 | 17/6/2026 | SAP Commerce Backoffice does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability causing low impact on confidentiality and integrity of the application. | |
| Modificada | Alta (7.5) | 5.3% | — | KDE Koffice | 20/8/2012 | 16/6/2026 | Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in KOffice 2.3.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this… | |
| Modificada | Media (6.8) | 4.2% | — | KDE Koffice | 3/12/2006 | 16/6/2026 | Integer overflow in the KPresenter import filter for Microsoft PowerPoint files (filters/olefilters/lib/klaola.cc) in KOffice before 1.6.1 allows user-assisted remote attackers to execute arbitrary code via a crafted PPT file, which results in a heap-based buffer overflow. | |
| Modificada | Media (5) | 3.4% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference. | |
| Modificada | Media (5) | 2.3% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows. | |
| Modificada | Alta (10) | 3.8% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins." | |
| Modificada | Media (4.3) | 1.4% | — | Comersus Open Technologies Comersus Backoffice LiteComersus Open Technologies Comersus Backoffice Plus | 1/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Comersus BackOffice allows remote attackers to inject arbitrary web script or HTML via the error parameter to comersus_backoffice_supportError.asp. NOTE: the comersus_backoffice_message.asp/message vector is already covered by CVE-2005-2191 item 2. | |
| Modificada | Media (4.3) | 3.5% | — | Comersus Open Technologies Comersus Backoffice Plus | 23/10/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in comersus_backoffice_searchItemForm.asp in Comersus BackOffice Plus allows remote attackers to inject arbitrary web script or HTML via the (1) forwardTo1, (2) forwardTo2, (3) nameFT1, or (4) nameFT2 parameters. | |
| Modificada | Alta (7.5) | 6.4% | — | KDE Koffice | 20/10/2005 | 16/6/2026 | Heap-based buffer overflow in the KWord RTF importer for KOffice 1.2.0 through 1.4.1 allows remote attackers to execute arbitrary code via a crafted RTF file. | |
| Modificada | Media (4.3) | 1.2% | — | Comersus Open Technologies Comersus Backoffice Lite | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in (1) comersus_supportError.asp or (2) comersus_backofficelite_supportError.asp in BackOffice Lite 6.0 and 6.01 allow remote attackers to inject arbitrary web script or HTML via the error parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Comersus Open Technologies Comersus Backoffice Lite | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in default.asp in BackOffice Lite 6.0 and 6.01 allows remote attackers to execute arbitrary SQL commands via the referer field in the HTTP header. | |
| Modificada | Alta (7.5) | 1.6% | — | Comersus Open Technologies Comersus Backoffice Lite | 2/5/2005 | 16/6/2026 | comersus_backoffice_install10.asp in BackOffice Lite 6.0 and 6.01 allows remote attackers to bypass authentication and gain privileges via a direct request to the program. | |
| Modificada | Alta (7.5) | 3.0% | — | Ascii PtexCstex CstetexEasy Software Products CupsGnome Gpdf+18 | 27/4/2005 | 16/6/2026 | The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities. | |
| Modificada | Alta (10) | 6.2% | — | Easy Software Products CupsGnome GpdfKDE KofficeKDE Kpdf+12 | 27/1/2005 | 16/6/2026 | Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888. | |
| Modificada | Alta (10) | 9.5% | — | Easy Software Products CupsGnome GpdfKDE KofficeKDE Kpdf+12 | 27/1/2005 | 16/6/2026 | Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889. | |
| Modificada | Alta (10) | 32% | — | Microsoft Backoffice | 12/8/2002 | 16/6/2026 | Microsoft BackOffice 4.0 and 4.5, when configured to be accessible by other systems, allows remote attackers to bypass authentication and access the administrative ASP pages via an HTTP request with an authorization type (auth_type) that is not blank. | |
| Modificada | Alta (7.5) | 5.8% | — | Microsoft Backoffice Resource KIT | 22/2/1999 | 16/6/2026 | Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting. | |
| Modificada | Baja (2.1) | 4.2% | — | Microsoft Windows 2000Microsoft Windows NTMicrosoft Backoffice | 12/2/1999 | 16/6/2026 | The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted. |