Skip to content
Toggle Navigation
Kit ISO 27001
Ingeniería y Consultoría
Recursos
ISO 27001
ISO 27001 – GAP Analysis Tool
Ciberseguridad
Vulnerabilidades CVE
Blog
Contacto
Obtener el Toolkit
Toggle Navigation
Kit ISO 27001
Ingeniería y Consultoría
Recursos
ISO 27001
ISO 27001 – GAP Analysis Tool
Ciberseguridad
Vulnerabilidades CVE
Blog
Contacto
Obtener el Toolkit
Vulnerabilidades CVE
Vulnerabilidades CVE
drmunozcl
2025-06-04T18:44:58-04:00
Vulnerabilidades CVE
A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:
Severidad:
Todas
NONE
LOW
MEDIUM
HIGH
CRITICAL
UNKNOWN
CVE:
Aplicar
Borrar filtros
CVE ID
Publicado
Severidad
CVSS
Descripción
CVE-2026-58247
2026-08-11
MEDIUM
5.3
SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This could disclose limited, non-sensitive data from previously used memory, leading…
CVE-2026-58245
2026-08-11
LOW
3.8
SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of the application to perform authorization check to access certain functionalities in…
CVE-2026-58244
2026-08-11
MEDIUM
4.3
SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain application function, allowing a low-privileged authenticated attacker to access information that should be restricted…
CVE-2026-58243
2026-08-11
HIGH
8.8
SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS…
CVE-2026-58241
2026-08-11
MEDIUM
4.2
SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard) allows a low-privileged user to modify configuration tables that control access to data objects…
CVE-2026-58239
2026-08-11
LOW
3.7
SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send specially crafted requests to spoof the tenant context under conditions not fully…
CVE-2026-58238
2026-08-11
MEDIUM
5.9
SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input that causes the component to crash and restart. Successful…
CVE-2026-58237
2026-08-11
MEDIUM
5.9
WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit this to access restricted functionality. Successful exploitation could…
CVE-2026-58236
2026-08-11
MEDIUM
5.5
SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing security controls on an internal code path leading to operating system…
CVE-2026-58235
2026-08-11
MEDIUM
6.3
SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer libraries that contain known vulnerabilities addressed in later versions. A low-privileged authenticated…
CVE-2026-58230
2026-08-11
HIGH
7.0
SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be…
CVE-2026-47702
2026-08-11
N/A
0.0
TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the builder API) are stored in the database as cleartext strings.…
CVE-2026-50063
2026-08-11
HIGH
7.8
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains…
CVE-2026-50061
2026-08-11
HIGH
7.8
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain…
CVE-2026-50058
2026-08-11
HIGH
7.8
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains…
CVE-2026-44765
2026-08-11
HIGH
7.3
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access scheduling-related application functions without proper authorization validation. Successful exploitation…
CVE-2026-33922
2026-08-11
MEDIUM
6.0
A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to insufficient validation of an input parameter. A local user with…
CVE-2026-33921
2026-08-11
MEDIUM
5.2
The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead…
CVE-2026-44764
2026-08-11
HIGH
7.3
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parameter values.…
CVE-2026-44763
2026-08-11
HIGH
7.6
SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user…
CVE-2026-44762
2026-08-11
LOW
3.7
SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks certain restrictive directives, which could enable an authenticated malicious user to leverage…
CVE-2026-44758
2026-08-11
CRITICAL
9.1
SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful…
CVE-2026-40130
2026-08-11
MEDIUM
5.3
SAP SAPSPrint Service has memory corruption vulnerabilities in the handling of certain commands. An unauthenticated attacker could send specially crafted requests that trigger a buffer overflow in the…
CVE-2026-34265
2026-08-11
CRITICAL
9.8
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system…
CVE-2026-18635
2026-08-11
HIGH
7.2
Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able to run as a different user,…
CVE-2026-18127
2026-08-11
HIGH
7.7
External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket…
CVE-2026-18125
2026-08-11
HIGH
7.5
An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service.
CVE-2026-18348
2026-08-11
MEDIUM
4.1
Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the…
CVE-2026-13739
2026-08-11
N/A
0.0
A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance…
CVE-2026-12051
2026-08-11
MEDIUM
4.6
The USB DFU class implementation in Zephyr's new (experimental) device_next USB device stack contains a NULL pointer dereference in handle_download() (subsys/usb/device_next/class/usbd_dfu.c). The handler computes MIN(setup->wLength, buf->len) and passes…
CVE-2026-11810
2026-08-10
HIGH
7.5
The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_probe() in subsys/mgmt/updatehub/updatehub.c) parses the JSON metadata returned by the update server into a fixed two-level nested-array struct. After parsing it validates…
CVE-2026-12339
2026-08-10
N/A
0.0
A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite arbitrary…
CVE-2026-12624
2026-08-10
MEDIUM
4.3
Vault’s ACL policy engine did not consistently enforce a wildcard (glob) deny rule against LIST requests made with a trailing slash on the denied path. This may allow…
CVE-2026-11809
2026-08-10
LOW
3.7
The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c contains an out-of-bounds / uninitialized-memory read in z_impl_updatehub_probe(). The probe response from the UpdateHub server is copied into a heap buffer (metadata)…
CVE-2025-30239
2026-08-10
N/A
0.0
In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data may allow an attacker who has access to device…
CVE-2025-32736
2026-08-10
N/A
0.0
Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may allow actors to perform unauthorized actions via specially-crafted links triggered by administrators with…
CVE-2025-30238
2026-08-10
N/A
0.0
In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to execute higher-privileged operations. An attacker may perform administrative actions such as creating privileged accounts or…
CVE-2023-54374
2026-08-11
N/A
0.0
Rejected reason: This CVE ID has been rejected.
CVE-2023-54373
2026-08-11
N/A
0.0
Rejected reason: This CVE ID has been rejected.
CVE-2023-54372
2026-08-11
N/A
0.0
Rejected reason: This CVE ID has been rejected.
CVE-2023-54371
2026-08-11
N/A
0.0
Rejected reason: This CVE ID has been rejected.
CVE-2023-54370
2026-08-11
N/A
0.0
Rejected reason: This CVE ID has been rejected.
CVE-2023-54369
2026-08-11
N/A
0.0
Rejected reason: This CVE ID has been rejected.
CVE-2023-54368
2026-08-11
N/A
0.0
Rejected reason: This CVE ID has been rejected.
CVE-2023-54367
2026-08-11
N/A
0.0
Rejected reason: This CVE ID has been rejected.
CVE-2022-50974
2026-08-11
N/A
0.0
Rejected reason: This CVE ID has been rejected.
CVE-2021-47995
2026-08-11
N/A
0.0
Rejected reason: This CVE ID has been rejected.
CVE-2021-47994
2026-08-11
N/A
0.0
Rejected reason: This CVE ID has been rejected.
CVE-2025-30237
2026-08-10
N/A
0.0
The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not consistently enforced on certain endpoints. An attacker can send specially crafted…
CVE-2021-47993
2026-08-11
N/A
0.0
Rejected reason: This CVE ID has been rejected.
« Anterior
Página 65 de 4840
Siguiente »
Page load link
Go to Top