Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
2261 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.32% | — | SAP Businessobjects Business Intelligence PlatformAI | 9/12/2025 | 7/10/2026 | SAP BusinessObjects Business Intelligence Platform lets an unauthenticated remote attacker send crafted requests through the URL parameter that controls the login page error message. This can cause the server to fetch attacker-supplied URLs, resulting in low impact to confidentiality and integrity, and no impact to… | |
| Aplazada | Media (5.5) | 0.31% | — | SAP Enterprise Search FOR AbapAI | 9/12/2025 | 7/10/2026 | Due to a missing authorization check in SAP Enterprise Search for ABAP, an attacker with high privileges may read and export the contents of database tables into an ABAP report. This could lead to a high impact on data confidentiality and a low impact on data integrity. There is no impact on application's availability. | |
| Aplazada | Crítica (9.9) | 4.5% | — | SAP Solution ManagerAI | 9/12/2025 | 7/10/2026 | Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to high impact on confidentiality, integrity and availability of the system. | |
| Aplazada | Alta (8.2) | 0.36% | — | SAP WEB DispatcherAISAP ICMAI | 9/12/2025 | 7/10/2026 | SAP Web Dispatcher and ICM may expose internal testing interfaces that are not intended for production. If enabled, unauthenticated attackers could exploit them to access diagnostics, send crafted requests, or disrupt services. This vulnerability has a high impact on confidentiality, availability and low impact on… | |
| Aplazada | Alta (7.5) | 0.54% | — | SAP WEB DispatcherAISAP Internet Communication ManagerAISAP Content ServerAI | 9/12/2025 | 7/10/2026 | SAP Web Dispatcher, Internet Communication Manager (ICM), and SAP Content Server allow an unauthenticated user to exploit logical errors that lead to a memory corruption vulnerability. This results in high impact on the availability with no impact on confidentiality or integrity of the application. | |
| Aplazada | Alta (7.1) | 0.30% | — | SAP S/4 Hana Private CloudAI | 9/12/2025 | 7/10/2026 | Due to a Missing Authorization Check vulnerability in SAP S/4 HANA Private Cloud (Financials General Ledger), an authenticated attacker with authorization limited to a single company code could read sensitive data and post or modify documents across all company codes. Successful exploitation could result in a high… | |
| Aplazada | Media (6.6) | 0.34% | — | SAP Internet Communication FrameworkAI | 9/12/2025 | 7/10/2026 | The SAP Internet Communication Framework does not conduct any authentication checks for features that need user identification allowing an attacker to reuse authorization tokens, violating secure authentication practices causing low impact on Confidentiality, Integrity and Availability of the application. | |
| Aplazada | Alta (7.9) | 0.47% | — | SAP NetweaverAISAP XcelsiusAI | 9/12/2025 | 7/10/2026 | SAP NetWeaver remote service for Xcelsius allows an attacker with network access and high privileges to execute arbitrary code on the affected system due to insufficient input validation and improper handling of remote method calls. Exploitation does not require user interaction and could lead to service disruption or… | |
| Aplazada | Media (5.9) | 0.38% | — | Sapui5AIMarkdown-itAISAP Openui5AI | 9/12/2025 | 7/10/2026 | SAPUI5 (and OpenUI5) packages use outdated 3rd party libraries with known security vulnerabilities. When markdown-it encounters special malformed input, it fails to terminate properly, resulting in an infinite loop. This Denial of Service via infinite loop causes high CPU usage and system unresponsiveness due to a… | |
| Aplazada | Media (6.1) | 0.26% | — | SAP Netweaver Enterprise PortalAI | 9/12/2025 | 7/10/2026 | Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, an unauthenticated attacker could inject malicious scripts that execute in the context of other users� browsers, allowing the attacker to steal session cookies, tokens, and other sensitive information. As a result, the vulnerability… | |
| Aplazada | Alta (8.6) | 0.30% | — | Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+28 | 19/11/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,… | |
| Aplazada | Alta (8.6) | 0.30% | — | Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+28 | 19/11/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,… | |
| Analizada | Media (5.4) | 0.17% | — | WhatsappWhatsapp Business | 18/11/2025 | 17/6/2026 | Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device. We have not seen evidence of exploitation in… | |
| Aplazada | Alta (7.5) | 0.43% | — | SAP CommoncryptolibAI | 11/11/2025 | 17/6/2026 | SAP CommonCryptoLib does not perform necessary boundary checks during pre-authentication parsing of manipulated ASN.1 data over the network. This may result in memory corruption followed by an application crash, hence leading to a high impact on availability. There is no impact on confidentiality or integrity. | |
| Aplazada | Media (6.1) | 0.21% | — | SAP E RecruitingAISAP S/4hanaAI | 11/11/2025 | 17/6/2026 | SAP S/4HANA landscape SAP E-Recruiting BSP allows an unauthenticated attacker to craft malicious links, when clicked the victim could be redirected to the page controlled by the attacker. This has low impact on confidentiality and integrity of the application with no impact on availability. | |
| Aplazada | Media (5.3) | 0.46% | — | SAP Netweaver Application Server JavaAI | 11/11/2025 | 17/6/2026 | Due to an Information Disclosure vulnerability in SAP NetWeaver Application Server Java, internal metadata files could be accessed via manipulated URLs. An unauthenticated attacker could exploit this vulnerability by inserting arbitrary path components in the request, allowing unauthorized access to sensitive… | |
| Aplazada | Media (4.3) | 0.24% | — | SAP S4coreAI | 11/11/2025 | 17/6/2026 | SAP S4CORE (Manage journal entries) does not perform necessary authorization checks for an authenticated user resulting in escalation of privileges. This has low impact on confidentiality of the application with no impact on integrity and availability of the application. | |
| Aplazada | Media (5.3) | 0.23% | — | SAP Business ONEAI | 11/11/2025 | 17/6/2026 | Due to information disclosure vulnerability in anonymous API provided by SAP Business One (SLD), an attacker with normal user access could gain access to unauthorized information. As a result, it has a low impact on the confidentiality of the application but no impact on the integrity and availability. | |
| Aplazada | Media (6.9) | 0.16% | — | SAP Hana Jdbc ClientAI | 11/11/2025 | 17/6/2026 | Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a high-privilege locally authenticated user to supply crafted parameters that lead to unauthorized code loading, resulting in low impact on confidentiality and integrity and high impact on availability of the application. | |
| Analizada | Media (6.8) | 0.28% | — | SAP Business Connector | 11/11/2025 | 17/6/2026 | Due to a Path Traversal vulnerability in SAP Business Connector, an attacker authenticated as an administrator with adjacent access could read, write, overwrite, and delete arbitrary files on the host system. Successful exploitation could enable the attacker to execute arbitrary operating system commands on the… | |
| Analizada | Media (6.1) | 0.23% | — | SAP Business Connector | 11/11/2025 | 17/6/2026 | Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL that, if accessed by a victim, redirects them to an attacker-controlled site displayed within an embedded frame. Successful exploitation could allow the attacker to steal sensitive information and… | |
| Analizada | Media (6.8) | 0.81% | — | SAP Business Connector | 11/11/2025 | 17/6/2026 | Due to an OS Command Injection vulnerability in SAP Business Connector, an authenticated attacker with administrative access and adjacent network access could upload specially crafted content to the server. If processed by the application, this content enables execution of arbitrary operating system commands.… | |
| Aplazada | Crítica (10) | 0.69% | — | SAP SQL Anywhere MonitorAI | 11/11/2025 | 17/6/2026 | SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended users and providing attackers with the possibility of arbitrary code execution.This could cause high impact on confidentiality integrity and availability of the system. | |
| Aplazada | Media (5.4) | 0.19% | — | SAP Starter SolutionAI | 11/11/2025 | 17/6/2026 | SAP Starter Solution allows an authenticated attacker to execute crafted database queries, thereby exposing the back-end database. As a result, this vulnerability has a low impact on the application's confidentiality and integrity but no impact on its availability. | |
| Aplazada | Media (5.5) | 0.11% | — | SAP GUI FOR WindowsAI | 11/11/2025 | 17/6/2026 | SAP GUI for Windows may allow a highly privileged user on the affected client PC to locally access sensitive information stored in process memory during runtime.This vulnerability has a high impact on confidentiality, with no impact on integrity and availability. |