Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.8) | 0.53% | — | SAP Netweaver Message ServerAI | 8/9/2026 | 9/9/2026 | SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized… | |
| Modificada | Alta (8.8) | 0.53% | — | SAP Message Server | 8/8/2023 | 17/6/2026 | The ACL (Access Control List) of SAP Message Server - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, RNL64UC 7.22, RNL64UC 7.22EXT, RNL64UC 7.53, KRNL64NUC 7.22, KRNL64NUC 7.22EXT, can be bypassed in certain conditions, which may enable an authenticated malicious user to enter the network of the SAP… | |
| Modificada | Alta (10) | 46% | 💥 Exploit | Bigantsoft Bigant IM Message Server | 24/2/2013 | 16/6/2026 | Multiple stack-based buffer overflows in AntDS.exe in BigAntSoft BigAnt IM Message Server allow remote attackers to have an unspecified impact via (1) the filename header in an SCH request or (2) the userid component in a DUPF request. | |
| Modificada | Media (5) | 47% | 💥 Exploit | Bigantsoft Bigant IM Message Server | 24/2/2013 | 16/6/2026 | BigAntSoft BigAnt IM Message Server does not require authentication for file uploading, which allows remote attackers to create arbitrary files under AntServer\DocData\Public via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.3% | — | Bigantsoft Bigant IM Message Server | 24/2/2013 | 16/6/2026 | SQL injection vulnerability in BigAntSoft BigAnt IM Message Server allows remote attackers to execute arbitrary SQL commands via an SHU (aka search user) request. | |
| Modificada | Alta (10) | 37% | 💥 Exploit | SAP Message Server | 9/7/2007 | 16/6/2026 | Heap-based buffer overflow in the Message HTTP Server in SAP Message Server allows remote attackers to execute arbitrary code via a long string in the group parameter to /msgserver/html/group. | |
| Modificada | Alta (7.5) | 22% | 💥 Exploit | Sendmail Advanced Message ServerSendmailSendmail PROSendmail Switch+10 | 6/10/2003 | 16/6/2026 | A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences. | |
| Modificada | Alta (10) | 66% | — | Sendmail Advanced Message ServerSendmailSendmail PROSendmail Switch+14 | 6/10/2003 | 16/6/2026 | The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c. |