Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.83% | — | Unit4 Enterprise Resource Planning | 19/7/2022 | 17/6/2026 | Unit4 ERP through 7.9 allows XXE via ExecuteServerProcessAsynchronously. | |
| Modificada | Alta (7.5) | 1.0% | — | Dalmark Systeam Enterprise Resource Planning | 21/12/2021 | 17/6/2026 | Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to Incorrect Access Control. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts. A broken access control vulnerability has been found while… | |
| Modificada | Media (5.3) | 0.79% | — | Dalmark Systeam Enterprise Resource Planning | 21/12/2021 | 17/6/2026 | Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts. This issue occurs during the identification of the correct tenant for… | |
| Modificada | Media (5.3) | 0.79% | — | Dalmark Systeam Enterprise Resource Planning | 21/12/2021 | 17/6/2026 | Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts. This issue occurs during the password recovery procedure for a given… | |
| Modificada | Alta (8.8) | 1.0% | — | Dalmark Systeam Enterprise Resource Planning | 21/12/2021 | 17/6/2026 | Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to Insecure design on report build via SQL query. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts. The bi report module exposes direct SQL… | |
| Modificada | Media (5.4) | 0.59% | — | Junhetec Enterprise Resource Planning Point OF Sale System | 7/5/2021 | 17/6/2026 | Special characters of ERP POS news page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks, additionally access and manipulate customer’s information. | |
| Modificada | Media (5.4) | 0.59% | — | Junhetec Enterprise Resource Planning Point OF Sale System | 7/5/2021 | 17/6/2026 | Special characters of ERP POS customer profile page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks, additionally access and manipulate customer’s information. | |
| Modificada | Media (6.5) | 0.74% | — | Web-school Enterprise Resource Planning | 8/4/2021 | 17/6/2026 | Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a voucher payment request through module/accounting/voucher/create. The application fails to validate the CSRF token for a POST request using admin privilege. | |
| Modificada | Media (6.1) | 0.95% | — | Web-school Enterprise Resource Planning | 8/4/2021 | 17/6/2026 | A blind XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in event name and description fields. An attacker can inject a JavaScript code that will be stored in the page. If any visitor sees the event, then the payload will be executed and sends the victim's information to the attacker website. | |
| Modificada | Media (6.5) | 0.74% | — | Web-school Enterprise Resource Planning | 8/4/2021 | 17/6/2026 | Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a student_leave_application request through module/core/studentleaveapplication/create. The application fails to validate the CSRF token for a POST request using Guardian privilege. | |
| Modificada | Media (5.4) | 0.73% | — | Web-school Enterprise Resource Planning | 8/4/2021 | 17/6/2026 | A stored XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in the event name and description fields. An attack can inject a JavaScript code that will be stored in the page. If any visitor sees the events, then the payload will be executed. | |
| Modificada | Alta (7.5) | 1.3% | — | SAP Enterprise Resource Planning | 22/1/2015 | 17/6/2026 | The Dealer Portal in SAP ERP does not properly restrict access, which allows remote attackers to obtain sensitive information, gain privileges, and possibly have other unspecified impact via unknown vectors, aka SAP Note 2000401. NOTE: the provenance of this information is unknown; the details are obtained solely from… |