Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2637▼ 209 respecto a la semana anterior
Críticas / altas1378▲ 149 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.1% | — | Microsoft Dynamics GP | 9/2/2022 | 17/6/2026 | Microsoft Dynamics GP Remote Code Execution Vulnerability | |
| Modificada | Alta (8.8) | 2.2% | — | Microsoft Dynamics GP | 9/2/2022 | 17/6/2026 | Microsoft Dynamics GP Elevation Of Privilege Vulnerability | |
| Modificada | Alta (8.8) | 2.5% | — | Microsoft Dynamics GP | 9/2/2022 | 17/6/2026 | Microsoft Dynamics GP Elevation Of Privilege Vulnerability | |
| Modificada | Alta (8.8) | 3.8% | — | Microsoft Dynamics GP | 9/2/2022 | 17/6/2026 | Microsoft Dynamics GP Elevation Of Privilege Vulnerability | |
| Modificada | Media (5.4) | 1.2% | — | Microsoft Dynamics GP | 9/2/2022 | 17/6/2026 | Microsoft Dynamics GP Spoofing Vulnerability | |
| Modificada | Media (4) | 8.5% | — | Microsoft Dynamics GP | 26/5/2010 | 16/6/2026 | Microsoft Dynamics GP has a default value of ACCESS for the system password, which might make it easier for remote authenticated users to bypass intended access restrictions via unspecified vectors. | |
| Modificada | Media (4) | 11% | — | Microsoft Dynamics GP | 21/5/2010 | 16/6/2026 | Microsoft Dynamics GP uses a substitution cipher to encrypt the system password field and unspecified other fields, which makes it easier for remote authenticated users to obtain sensitive information by decrypting a field's contents. | |
| Modificada | Alta (7.5) | 16% | — | Microsoft Dynamics GP | 31/12/2006 | 16/6/2026 | Multiple buffer overflows in Microsoft Dynamics GP (formerly Great Plains) 9.0 and earlier allow remote attackers to execute arbitrary code via (1) a crafted Distributed Process Manager (DPM) message to the (a) DPM component, or a (2) long string or (3) long IP address in a Distributed Process Server (DPS) message to… | |
| Modificada | Media (5) | 10% | — | Microsoft Dynamics GP | 31/12/2006 | 16/6/2026 | Unspecified vulnerability in Microsoft Dynamics GP (formerly Great Plains) 9.0 and earlier allows remote attackers to cause a denial of service (crash) via an invalid magic number in a Distributed Process Server (DPS) message. |