Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
2261 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.9) | 0.59% | — | SAP Solution ManagerAI | 11/11/2025 | 17/6/2026 | Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to high impact on confidentiality, integrity and availability of the system. | |
| Analizada | Media (6.1) | 0.24% | — | SAP Business Connector | 11/11/2025 | 17/6/2026 | Due to a Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated victim accesses this link, the injected input is processed during web page generation, resulting in the execution of… | |
| Aplazada | Media (5.8) | 0.31% | — | SAP HanaAI | 11/11/2025 | 17/6/2026 | Due to missing authentication, SAP HANA 2.0 (hdbrss) allows an unauthenticated attacker to call a remote-enabled function that will enable them to view information. As a result, it has a low impact on the confidentiality but no impact on the integrity and availability of the system. | |
| Aplazada | Media (6.5) | 0.26% | — | SAP Netweaver Enterprise PortalAI | 11/11/2025 | 17/6/2026 | SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject JNDI environment properties or pass a URL used during JNDI lookup operations, enabling access to an unintended JNDI provider.�This could further lead to disclosure or modification of information about the server. There is no impact on… | |
| Aplazada | Baja (2.7) | 0.25% | — | SAP Netweaver Application Server FOR AbapAISAP Migration WorkbenchAISAP DX WorkbenchAI | 11/11/2025 | 17/6/2026 | Migration Workbench (DX Workbench) in SAP NetWeaver Application Server for ABAP fails to trigger a malware scan when an attacker with administrative privileges uploads files to the application server. An attacker could leverage this and upload a malicious file into the system. This results in a low impact on the… | |
| Aplazada | Media (4.3) | 0.23% | — | SAP Netweaver Application Server AbapAI | 11/11/2025 | 17/6/2026 | Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with basic privileges could execute a specific function module in ABAP to retrieve restricted technical information from the system. This disclosure of environment details of the system could further assist… | |
| Aplazada | Media (6.4) | 0.22% | — | Saphali LiqpayAI | 8/11/2025 | 7/10/2026 | The Saphali LiqPay for donate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'saphali_liqpay' shortcode in all versions up to, and including, 1.0.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Alta (7.3) | 0.28% | — | X.org X ServerX.org XwaylandIBM ViosIBM AIX+7 | 30/10/2025 | 1/7/2026 | A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect. | |
| Analizada | Alta (7.3) | 0.30% | — | X.org X ServerX.org XwaylandIBM ViosIBM AIX+7 | 30/10/2025 | 1/7/2026 | A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash. | |
| Aplazada | Alta (7.1) | 0.24% | — | Themewarriors Whatsapp Chat FOR Wordpress AND WoocommerceAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeWarriors WhatsApp Chat for WordPress and WooCommerce tw-whatsapp-chat-rotator allows Reflected XSS.This issue affects WhatsApp Chat for WordPress and WooCommerce: from n/a through <= 1.2.1. | |
| Aplazada | Alta (7.3) | 0.15% | — | Wallosapp WallosAI | 14/10/2025 | 5/7/2026 | A Cross-Site Request Forgery (CSRF) in the component /endpoints/currency/currency of Wallos v4.1.1 allows attackers to execute arbitrary operations via a crafted GET request. | |
| Aplazada | Crítica (9.8) | 0.74% | — | SAP Print ServiceAI | 14/10/2025 | 17/6/2026 | SAP Print Service (SAPSprint) performs insufficient validation of path information provided by users. An unauthenticated attacker could traverse to the parent directory and over-write system files causing high impact on confidentiality integrity and availability of the application. | |
| Aplazada | Crítica (9) | 0.48% | — | SAP Supplier Relationship ManagementAI | 14/10/2025 | 17/6/2026 | Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attacker to upload arbitrary files. These files could include executables which might be downloaded and executed by the user which could host malware. On successful exploitation an attacker could cause… | |
| Aplazada | Baja (3) | 0.24% | — | SAP Cloud Appliance LibraryAISAP S/4hanaAI | 14/10/2025 | 17/6/2026 | SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default profile setting in an existing SAP CAL appliances to gain access to other appliances. This has low impact on confidentiality of the application, integrity and availability is not impacted. | |
| Aplazada | Media (5.4) | 0.16% | — | SAP Netweaver Application Server FOR AbapAI | 14/10/2025 | 17/6/2026 | Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP, an authenticated attacker could initiate transactions directly via the session manager, bypassing the first transaction screen and the associated authorization check. This vulnerability could allow the attacker to… | |
| Aplazada | Media (5.3) | 0.43% | — | SAP Commerce CloudAI | 14/10/2025 | 17/6/2026 | SAP Commerce Cloud contains a path traversal vulnerability that may allow users to access web applications such as the Administration Console from addresses where the Administration Console is not explicitly deployed. This could potentially bypass configured access restrictions, resulting in a low impact on… | |
| Aplazada | Media (4.3) | 0.34% | — | SAP Financial Service Claims ManagementAI | 14/10/2025 | 17/6/2026 | A vulnerability in SAP Financial Service Claims Management RFC function ICL_USER_GET_NAME_AND_ADDRESS allows user enumeration and potential disclosure of personal data through response discrepancies, causing low impact on confidentiality with no impact on integrity or availability. | |
| Aplazada | Media (5.3) | 0.37% | — | SAP Netweaver AS AbapAISAP Abap PlatformAI | 14/10/2025 | 17/6/2026 | Due to the memory corruption vulnerability in SAP NetWeaver AS ABAP and ABAP Platform, an unauthenticated attacker can send a corrupted SAP Logon Ticket or SAP Assertion Ticket to the SAP application server. This leads to a dereference of NULL which makes the work process crash. As a result, it has a low impact on the… | |
| Aplazada | Media (5.4) | 0.23% | — | SAP Application Server FOR AbapAI | 14/10/2025 | 17/6/2026 | SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript payloads which could be executed in victim user's browser when accessing the affected functionality of BAPI explorer. This has low impact on confidentiality and integrity with no impact on availability of the application. | |
| Aplazada | Media (4.3) | 0.23% | — | SAP S/4hanaAI | 13/10/2025 | 30/9/2026 | SAP S/4HANA (Manage Processing Rules - For Bank Statements) allows an authenticated attacker with basic privileges to delete conditions from any shared rule of any user by tampering the request parameter. Due to missing authorization check, the attacker can delete shared rule conditions that should be restricted,… | |
| Aplazada | Media (4.3) | 0.22% | — | SAP BI PlatformAI | 23/9/2025 | 17/6/2026 | SAP BI Platform allows an attacker to modify the IP address of the LogonToken for the OpenDoc. On accessing the modified link in the browser a different server could get the ping request. This has low impact on integrity with no impact on confidentiality and availability of the system. | |
| Aplazada | Media (5.9) | 0.30% | — | Sapo FeedAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SAPO SAPO Feed sapo-feed allows Stored XSS.This issue affects SAPO Feed: from n/a through <= 2.4.2. | |
| Aplazada | Crítica (9.1) | 0.69% | — | SAP NetweaverAIIBM I-seriesAI | 9/9/2025 | 17/6/2026 | Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the application allows high privileged unauthorized users to read, modify, or delete sensitive information, as well as access administrative or privileged functionalities. This results in a high impact on the confidentiality,… | |
| Aplazada | Crítica (10) | 2.9% | 💥 PoC | SAP NetweaverAI | 9/9/2025 | 17/6/2026 | Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through the RMI-P4 module by submitting malicious payload to an open port. The deserialization of such untrusted Java objects could lead to arbitrary OS command execution, posing a high impact to the… | |
| Aplazada | Media (6.1) | 0.22% | — | SAP Netweaver Abap PlatformAI | 9/9/2025 | 17/6/2026 | Due to a Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is processed during the website�s page generation, resulting in the… |