Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

31 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (4.1)0.26%—SAP CRM Webclient UIAI14/7/202614/7/2026
SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of the application due to the absence of a Content Security Policy (CSP) configuration for certain restrictive directives. This vulnerability has a low impact on the integrity of the application. Confidentiality and…
AnalizadaCrítica (9.9)0.52%—SAP Netweaver Application Server AbapSAP S/4hanaSAP Webclient UI Framework10/2/202617/6/2026
An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impact on…
ModificadaMedia (6.5)0.30%—SAP Customer Relationship Management S4fndSAP Customer Relationship Management Webclient UI9/7/202417/6/2026
SAP CRM WebClient does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to access some sensitive information.
ModificadaAlta (7.7)0.31%—SAP Customer Relationship Management S4fndSAP Customer Relationship Management Webclient UI9/7/202417/6/2026
SAP CRM (WebClient UI Framework) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in information disclosure. It has no impact on integrity and availability of the application.
ModificadaMedia (6.1)0.26%—SAP Customer Relationship Management S4fndSAP Customer Relationship Management Webclient UI9/7/202417/6/2026
Custom CSS support option in SAP CRM WebClient UI does not sufficiently encode user-controlled inputs resulting in Cross-Site Scripting vulnerability. On successful exploitation an attacker can cause limited impact on confidentiality and integrity of the application.
ModificadaMedia (6.1)0.27%—SAP Customer Relationship Management S4fndSAP Customer Relationship Management Webclient UI9/7/202417/6/2026
—
ModificadaMedia (6.1)0.27%—SAP Customer Relationship Management Webclient UI11/6/202417/6/2026
Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script. When a victim clicks on this link, the script will be executed in the victim's browser giving the attacker the ability to access and/or modify information with no effect on…
ModificadaMedia (4.1)0.33%—SAP CRM - Webclient UI13/2/202417/6/2026
SAP CRM WebClient UI - version S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker with low privileges…
ModificadaMedia (5.4)0.32%—SAP CRM - Webclient UI13/2/202417/6/2026
Print preview option in SAP CRM WebClient UI - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, S4FND 108, WEBCUIF 700, WEBCUIF 701, WEBCUIF 730, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode user-controlled inputs, resulting in…
ModificadaMedia (6.1)0.50%—Icewarp Webclient25/9/202317/6/2026
Cross Site Scripting (XSS) vulnerability in the Sign-In page of IceWarp WebClient 10.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter.
ModificadaMedia (6.1)1.5%—Icewarp Webclient5/9/202317/6/2026
Cross Site Scripting vulnerability in IceWarp Corporation WebClient v.10.2.1 allows a remote attacker to execute arbitrary code via a crafted payload to the mid parameter.
ModificadaMedia (6.1)0.44%—SAP Customer Relationship Management S4fndSAP Customer Relationship Management Webclient UI9/5/202317/6/2026
SAP CRM (WebClient UI) - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, WEBCUIF 700, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode user-controlled inputs, resulting in a stored Cross-Site Scripting (XSS)…
ModificadaMedia (5.4)0.37%—SAP Customer Relationship Management Webclient UISAP S4fndSapscore9/5/202317/6/2026
SAP CRM WebClient UI - versions SAPSCORE 129, S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After…
ModificadaMedia (5.4)0.44%—SAP Customer Relationship Management S4fndSAP Customer Relationship Management Webclient UI11/4/202317/6/2026
SAP CRM (WebClient UI) - versions S4FND 102, 103, 104, 105, 106, 107, WEBCUIF, 700, 701, 731, 730, 746, 747, 748, 800, 801, allows an authenticated attacker to modify HTTP verbs used in requests to the web server. This application is exposed over the network and successful exploitation can lead to exposure of form…
ModificadaMedia (5.4)0.34%—SAP Customer Relationship Management Webclient UISAP S4fnd14/2/202317/6/2026
SAP CRM WebClient UI - versions WEBCUIF 748, 800, 801, S4FND 102, 103, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. On successful exploitation an authenticated attacker can cause limited impact on confidentiality of the application.
ModificadaCrítica (9.8)0.77%—Icewarp Webclient DC223/8/202217/6/2026
IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was discovered to contain a SQL injection vulnerability via the search parameter at /webmail/server/webmail.php.
ModificadaCrítica (9.8)1.2%—Allgeier Metasonic DOC Webclient16/5/202217/6/2026
Metasonic Doc WebClient 7.0.14.0 / 7.0.12.0 / 7.0.3.0 is vulnerable to a SQL injection attack in the username field. SSO or System authentication are required to be enabled for vulnerable conditions to exist.
ModificadaMedia (6.1)0.76%—Siemens Polarion ALMSiemens Polarion Subversion Webclient8/3/202217/6/2026
A vulnerability has been identified in Polarion ALM (All versions < V21 R2 P2), Polarion WebClient for SVN (All versions). A cross-site scripting is present due to improper neutralization of data sent to the web page through the SVN WebClient in the affected product. An attacker could exploit this to execute arbitrary…
ModificadaMedia (6.1)1.0%—Icewarp Webclient7/7/202117/6/2026
Cross Site Scripting (XSS) in Webmail Calender in IceWarp WebClient 10.3.5 allows remote attackers to inject arbitrary web script or HTML via the "p4" field.
ModificadaAlta (8.1)0.49%—Siemens Polarion Subversion Webclient9/9/202017/6/2026
A vulnerability has been identified in Polarion Subversion Webclient (All versions). The web interface could allow a Cross-Site Request Forgery (CSRF) attack if an unsuspecting user is tricked into accessing a malicious link. Successful exploitation requires user interaction by a legitimate user, who must be…
ModificadaMedia (6.1)0.67%—Siemens Polarion Subversion Webclient9/9/202017/6/2026
A vulnerability has been identified in Polarion Subversion Webclient (All versions). The Polarion subversion web application does not filter user input in a way that prevents Cross-Site Scripting. If a user is enticed into passing specially crafted, malicious input to the web client (e.g. by clicking on a malicious…
ModificadaMedia (6.1)0.84%—Icewarp Webclient11/10/201916/6/2026
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/ with the parameter password is non-persistent in 10.2.0.
ModificadaMedia (6.1)0.84%—Icewarp Webclient11/10/201916/6/2026
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][uid] is non-persistent in 10.1.3 and 10.2.0.
ModificadaMedia (6.1)0.84%—Icewarp Webclient11/10/201916/6/2026
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][action] is non-persistent in 10.1.3 and 10.2.0.
ModificadaMedia (6.1)0.84%—Icewarp Webclient11/10/201916/6/2026
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][controller] is non-persistent in 10.1.3 and 10.2.0.