Vulnerabilidades CVE

A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:

Borrar filtros
CVE ID Publicado Severidad CVSS Descripción
CVE-2026-58247 2026-08-11 MEDIUM 5.3 SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This could disclose limited, non-sensitive data from previously used memory, leading…
CVE-2026-58245 2026-08-11 LOW 3.8 SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of the application to perform authorization check to access certain functionalities in…
CVE-2026-58244 2026-08-11 MEDIUM 4.3 SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain application function, allowing a low-privileged authenticated attacker to access information that should be restricted…
CVE-2026-58243 2026-08-11 HIGH 8.8 SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS…
CVE-2026-58241 2026-08-11 MEDIUM 4.2 SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard) allows a low-privileged user to modify configuration tables that control access to data objects…
CVE-2026-58239 2026-08-11 LOW 3.7 SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send specially crafted requests to spoof the tenant context under conditions not fully…
CVE-2026-58238 2026-08-11 MEDIUM 5.9 SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input that causes the component to crash and restart. Successful…
CVE-2026-58237 2026-08-11 MEDIUM 5.9 WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit this to access restricted functionality. Successful exploitation could…
CVE-2026-58236 2026-08-11 MEDIUM 5.5 SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing security controls on an internal code path leading to operating system…
CVE-2026-58235 2026-08-11 MEDIUM 6.3 SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer libraries that contain known vulnerabilities addressed in later versions. A low-privileged authenticated…
CVE-2026-58230 2026-08-11 HIGH 7.0 SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be…
CVE-2026-47702 2026-08-11 N/A 0.0 TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the builder API) are stored in the database as cleartext strings.…
CVE-2026-50063 2026-08-11 HIGH 7.8 A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains…
CVE-2026-50061 2026-08-11 HIGH 7.8 A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain…
CVE-2026-50058 2026-08-11 HIGH 7.8 A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains…
CVE-2026-44765 2026-08-11 HIGH 7.3 Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access scheduling-related application functions without proper authorization validation. Successful exploitation…
CVE-2026-33922 2026-08-11 MEDIUM 6.0 A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to insufficient validation of an input parameter. A local user with…
CVE-2026-33921 2026-08-11 MEDIUM 5.2 The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead…
CVE-2026-44764 2026-08-11 HIGH 7.3 Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parameter values.…
CVE-2026-44763 2026-08-11 HIGH 7.6 SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user…
CVE-2026-44762 2026-08-11 LOW 3.7 SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks certain restrictive directives, which could enable an authenticated malicious user to leverage…
CVE-2026-44758 2026-08-11 CRITICAL 9.1 SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful…
CVE-2026-40130 2026-08-11 MEDIUM 5.3 SAP SAPSPrint Service has memory corruption vulnerabilities in the handling of certain commands. An unauthenticated attacker could send specially crafted requests that trigger a buffer overflow in the…
CVE-2026-34265 2026-08-11 CRITICAL 9.8 SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system…
CVE-2026-18635 2026-08-11 HIGH 7.2 Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able to run as a different user,…
CVE-2026-18127 2026-08-11 HIGH 7.7 External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket…
CVE-2026-18125 2026-08-11 HIGH 7.5 An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service.
CVE-2026-18348 2026-08-11 MEDIUM 4.1 Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the…
CVE-2026-13739 2026-08-11 N/A 0.0 A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance…
CVE-2026-12051 2026-08-11 MEDIUM 4.6 The USB DFU class implementation in Zephyr's new (experimental) device_next USB device stack contains a NULL pointer dereference in handle_download() (subsys/usb/device_next/class/usbd_dfu.c). The handler computes MIN(setup->wLength, buf->len) and passes…
CVE-2026-11810 2026-08-10 HIGH 7.5 The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_probe() in subsys/mgmt/updatehub/updatehub.c) parses the JSON metadata returned by the update server into a fixed two-level nested-array struct. After parsing it validates…
CVE-2026-12339 2026-08-10 N/A 0.0 A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite arbitrary…
CVE-2026-12624 2026-08-10 MEDIUM 4.3 Vault’s ACL policy engine did not consistently enforce a wildcard (glob) deny rule against LIST requests made with a trailing slash on the denied path. This may allow…
CVE-2026-11809 2026-08-10 LOW 3.7 The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c contains an out-of-bounds / uninitialized-memory read in z_impl_updatehub_probe(). The probe response from the UpdateHub server is copied into a heap buffer (metadata)…
CVE-2025-30239 2026-08-10 N/A 0.0 In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data may allow an attacker who has access to device…
CVE-2025-32736 2026-08-10 N/A 0.0 Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may allow actors to perform unauthorized actions via specially-crafted links triggered by administrators with…
CVE-2025-30238 2026-08-10 N/A 0.0 In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to execute higher-privileged operations. An attacker may perform administrative actions such as creating privileged accounts or…
CVE-2023-54374 2026-08-11 N/A 0.0 Rejected reason: This CVE ID has been rejected.
CVE-2023-54373 2026-08-11 N/A 0.0 Rejected reason: This CVE ID has been rejected.
CVE-2023-54372 2026-08-11 N/A 0.0 Rejected reason: This CVE ID has been rejected.
CVE-2023-54371 2026-08-11 N/A 0.0 Rejected reason: This CVE ID has been rejected.
CVE-2023-54370 2026-08-11 N/A 0.0 Rejected reason: This CVE ID has been rejected.
CVE-2023-54369 2026-08-11 N/A 0.0 Rejected reason: This CVE ID has been rejected.
CVE-2023-54368 2026-08-11 N/A 0.0 Rejected reason: This CVE ID has been rejected.
CVE-2023-54367 2026-08-11 N/A 0.0 Rejected reason: This CVE ID has been rejected.
CVE-2022-50974 2026-08-11 N/A 0.0 Rejected reason: This CVE ID has been rejected.
CVE-2021-47995 2026-08-11 N/A 0.0 Rejected reason: This CVE ID has been rejected.
CVE-2021-47994 2026-08-11 N/A 0.0 Rejected reason: This CVE ID has been rejected.
CVE-2025-30237 2026-08-10 N/A 0.0 The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not consistently enforced on certain endpoints. An attacker can send specially crafted…
CVE-2021-47993 2026-08-11 N/A 0.0 Rejected reason: This CVE ID has been rejected.
« Anterior Página 65 de 4840 Siguiente »