Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
2261 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.28% | — | SAP Business ONEAISAP SLDAI | 9/9/2025 | 17/6/2026 | When a user logs in via SAP Business One native client, the SLD backend service fails to enforce proper encryption of certain APIs. This leads to exposure of sensitive credentials within http response body. As a result, it has a high impact on the confidentiality, integrity, and availability of the application. | |
| Aplazada | Media (6.5) | 0.32% | — | SAP Business Planning AND ConsolidationAI | 9/9/2025 | 17/6/2026 | SAP Business Planning and Consolidation allows an authenticated standard user to call a function module by crafting specific parameters that causes a loop, consuming excessive resources and resulting in system unavailability. This leads to high impact on the availability of the application, there is no impact on… | |
| Aplazada | Alta (8.1) | 0.23% | — | SAP AbapAI | 9/9/2025 | 17/6/2026 | Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables are not protected by an authorization group. This leads to a high impact on integrity and availability of the database. | |
| Aplazada | Baja (3.4) | 0.14% | — | SAP Netweaver AS JavaAIAdobe Document ServiceAIOpensslAI | 9/9/2025 | 17/6/2026 | SAP NetWeaver AS Java application uses Adobe Document Service, installed with a vulnerable version of OpenSSL.Successful exploitation of known vulnerabilities in the outdated OpenSSL library would allow user with high system privileges to access and modify system information.This vulnerability has a low impact on… | |
| Analizada | Media (5.3) | 0.30% | — | SAP Netweaver Application Server Java | 9/9/2025 | 17/6/2026 | SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files within the web application.Upon successfully exploitation, an unauthenticated attacker could access these files to gather additional sensitive information about the system.This… | |
| Aplazada | Media (4.3) | 0.24% | — | SAP Netweaver AS JavaAI | 9/9/2025 | 17/6/2026 | Due to the lack of randomness in assigning Object Identifiers in the SAP NetWeaver AS JAVA IIOP service, an authenticated attacker with low privileges could predict the identifiers by conducting a brute force search. By leveraging knowledge of several identifiers generated close to the same time, the attacker could… | |
| Aplazada | Media (4.3) | 0.14% | — | SAP Fiori APP Manage Work Center GroupsAI | 9/9/2025 | 17/6/2026 | Due to insufficient CSRF protection in SAP Fiori App Manage Work Center Groups, an authenticated user could be tricked by an attacker to send unintended request to the web server. This has low impact on integrity and no impact on confidentiality and availability of the application. | |
| Aplazada | Crítica (9.9) | 0.72% | — | SAP Netweaver AS JavaAI | 9/9/2025 | 17/6/2026 | SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw in an available service to upload an arbitrary file. This file when executed can lead to a full compromise of confidentiality, integrity and availability of the system. | |
| Analizada | Media (6.1) | 0.26% | — | SAP Supplier Relationship Management | 9/9/2025 | 17/6/2026 | Due to a Cross-Site Scripting (XSS) vulnerability in the SAP Supplier Relationship Management, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated victim clicks on the link, the injected input is processed during the page generation, resulting in the… | |
| Analizada | Media (4.3) | 0.22% | — | SAP Basis | 9/9/2025 | 17/6/2026 | SAP NetWeaver Application Server for ABAP allows authenticated users with access to background processing to gain unauthorized read access to profile parameters. This results in a low impact on confidentiality, with no impact on integrity or availability | |
| Aplazada | Media (6.5) | 0.24% | — | SAP HCM Approve Timesheets FioriAI | 9/9/2025 | 17/6/2026 | SAP HCM Approve Timesheets Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This issue has a significant impact on the application's integrity, while confidentiality and availability remain unaffected. | |
| Aplazada | Media (5.4) | 0.19% | — | SAP FioriAI | 9/9/2025 | 17/6/2026 | Fiori app Manage Payment Blocks does not perform the necessary authorization checks, allowing an attacker with basic user privileges to abuse functionalities that should be restricted to specific user groups.This issue could impact both the confidentiality and integrity of the application without affecting the… | |
| Aplazada | Baja (3.1) | 0.21% | — | SAP HCM MY Timesheet FioriAI | 9/9/2025 | 17/6/2026 | Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and perform activities that are otherwise restricted, resulting in a low impact on the integrity of the application. Confidentiality and availability… | |
| Aplazada | Baja (3.1) | 0.21% | — | SAP HCM MY Timesheet FioriAI | 9/9/2025 | 17/6/2026 | Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and perform activities that are otherwise restricted, resulting in a low impact on the integrity of the application. Confidentiality and availability… | |
| Aplazada | Media (6.5) | 0.24% | — | SAP HCM MY Timesheet FioriAI | 9/9/2025 | 17/6/2026 | SAP HCM My Timesheet Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This issue has a significant impact on the application's integrity, while confidentiality and availability remain unaffected. | |
| Analizada | Media (4.3) | 0.22% | — | SAP Basis | 9/9/2025 | 17/6/2026 | SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled function module, which could grant access to information about the SAP system and operating system. This leads to a low impact on confidentiality, with no effect on the integrity and availability of the application | |
| En análisis | Media (5.4) | 4.7% | ⚠ Explotación activa💥 PoC | WhatsappWhatsapp Business | 29/8/2025 | 7/10/2026 | Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this… | |
| Aplazada | Alta (8.1) | 0.42% | — | SAP Netweaver Application Server AbapAI | 12/8/2025 | 17/6/2026 | SAP NetWeaver Application Server ABAP (BIC Document) allows an authenticated attacker to craft a request that, when submitted to a BIC Document application, could cause a memory corruption error. On successful exploitation, this results in the crash of the target component. Multiple submissions can make the target… | |
| Aplazada | Media (6.1) | 0.26% | — | SAP Netweaver Application Server AbapAISAP BIC DocumentAI | 12/8/2025 | 17/6/2026 | SAP NetWeaver Application Server ABAP (BIC Document) allows an unauthenticated attacker to craft a URL link which, when accessed on the BIC Document application, embeds a malicious script. When a victim clicks on this link, the script executes in the victim's browser, allowing the attacker to access and/or modify… | |
| Aplazada | Crítica (9.9) | 1.6% | 💥 PoC | SAP S/4hanaAI | 12/8/2025 | 17/6/2026 | SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full… | |
| Aplazada | Baja (3.5) | 0.46% | — | SAP Cloud ConnectorAI | 12/8/2025 | 17/6/2026 | Due to a missing authorization check in SAP Cloud Connector, an attacker on an adjacent network with low privileges could send a crafted request to the endpoint responsible for testing LDAP connections. A successful exploit could lead to reduced performance, hence a low-impact on availability of the service.… | |
| Aplazada | Alta (8.8) | 0.49% | — | SAP Business ONEAI | 12/8/2025 | 17/6/2026 | Due to broken authorization, SAP Business One (SLD) allows an authenticated attacker to gain administrator privileges of a database by invoking the corresponding API.�As a result , it has a high impact on the confidentiality, integrity, and availability of the application. | |
| Aplazada | Crítica (9.9) | 0.70% | — | SAP Landscape TransformationAI | 12/8/2025 | 17/6/2026 | SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor,… | |
| Aplazada | Media (4.9) | 0.32% | — | SAP Abap PlatformAI | 12/8/2025 | 17/6/2026 | Due to a missing authorization check in the ABAP Platform, an authenticated user with elevated privileges could bypass authorization restrictions for common transactions by leveraging the SQL Console. This could enable an attacker to access and read the contents of database tables without proper authorization, leading… | |
| Aplazada | Media (6.1) | 0.23% | — | SAP Netweaver Abap PlatformAI | 12/8/2025 | 17/6/2026 | Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is processed during the website�s page generation, resulting in the creation of… |