Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
2261 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.95% | — | SAP S/4hanaAI | 12/8/2025 | 17/6/2026 | Due to directory traversal vulnerability in SAP S/4HANA (Bank Communication Management), an attacker with high privileges and access to a specific transaction and method in Bank Communication Management could gain unauthorized access to sensitive operating system files. This could allow the attacker to potentially… | |
| Aplazada | Media (6.1) | 0.21% | — | SAP Netweaver Application Server AbapAI | 12/8/2025 | 17/6/2026 | SAP NetWeaver Application Server ABAP has HTML injection vulnerability. Due to this, an attacker could craft a URL with malicious script as payload and trick a victim with active user session into executing it. Upon successful exploit, this vulnerability could lead to limited access to data or its manipulation. There… | |
| Aplazada | Media (4.5) | 0.32% | — | SAP GUI FOR WindowsAISAP Application Server AbapAI | 12/8/2025 | 17/6/2026 | SAP GUI for Windows may allow the leak of NTML hashes when specific ABAP frontend services are called with UNC paths. For a successful attack, the attacker needs developer authorization in a specific Application Server ABAP to make changes in the code, and the victim needs to execute by using SAP GUI for Windows. This… | |
| Aplazada | Media (6.1) | 0.23% | — | SAP Netweaver Application Server AbapAI | 12/8/2025 | 17/6/2026 | SAP NetWeaver Application Server for ABAP has cross-site scripting vulnerability. Due to this, an unauthenticated attacker could craft a URL embedded with malicious script and trick an unauthenticated victim to click on it to execute the script. Upon successful exploitation, the attacker could access and modify… | |
| Aplazada | Baja (3.5) | 0.21% | — | SAP FioriAI | 12/8/2025 | 17/6/2026 | SAP Fiori (Launchpad) is vulnerable to Reverse Tabnabbing vulnerability due to inadequate external navigation protections for its link (<a>) elements. An attacker with administrative user privileges could exploit this by leveraging compromised or malicious pages. While administrative access is necessary for certain… | |
| Analizada | Media (5.4) | 0.20% | — | SAP Basis | 12/8/2025 | 17/6/2026 | The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations for different user roles, this issue allows authenticated users to access restricted objects in the barcode interface, leading to privilege escalation. This results in a low impact on the… | |
| Aplazada | Media (4.1) | 0.13% | — | SAP Netweaver Application Server AbapAISAP Abap PlatformAI | 12/8/2025 | 17/6/2026 | The SAP NetWeaver Application Server ABAP and ABAP Platform Internet Communication Manager (ICM) permits authorized users with admin privileges and local access to log files to read sensitive information, resulting in information disclosure. This leads to high impact on the confidentiality of the application, with no… | |
| Aplazada | Media (4.3) | 0.26% | — | SAP S/4hanaAI | 12/8/2025 | 17/6/2026 | SAP S/4HANA Supplier invoice is vulnerable to CRLF Injection. An attacker with user-level privileges can bypass the allowlist and insert untrusted sites into the 'Trusted Sites' configuration by injecting line feed (LF) characters into application inputs. This vulnerability has a low impact on the application's… | |
| Analizada | Alta (8.8) | 1.6% | ⚠ Explotación activa💥 PoC | Apple SafariApple IpadosApple Iphone OSApple Macos+11 | 29/7/2025 | 21/9/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption. | |
| Aplazada | Media (5.5) | 0.31% | — | SAP Fica ODN FrameworkAI | 23/7/2025 | 17/6/2026 | SAP FICA ODN framework allows a high privileged user to inject value inside the local variable which can then be executed by the application. An attacker could thereby control the behaviour of the application causing high impact on integrity, low impact on availability and no impact on confidentiality of the… | |
| Analizada | Media (6.1) | 0.69% | 💥 PoC | Sensaphone Web600 Firmware | 21/7/2025 | 17/6/2026 | Cross Site Scripting vulnerability in Sensaphone WEB600 Monitoring System v.1.6.5.H and before allows a remote attacker to execute arbitrary code via a crafted GET requests to /@.xml, placing payloads in the g7200, g7300, g4601, and g1F02 parameters. | |
| Aplazada | Baja (1.9) | 0.27% | — | Sapido Rb-1802AI | 14/7/2025 | 17/6/2026 | A vulnerability classified as problematic was found in Sapido RB-1802 1.0.32. This vulnerability affects unknown code of the file urlfilter.asp of the component URL Filtering Page. The manipulation of the argument URL address leads to cross site scripting. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Crítica (9.9) | 0.32% | — | Radiflow Isap Smart CollectorAI | 9/7/2025 | 17/6/2026 | An unauthenticated user with management network access can get and modify the Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) configuration. The device has two web servers that expose unauthenticated REST APIs on the management network (TCP ports 8084 and 8086). An attacker can use these APIs to get access to all… | |
| Aplazada | Alta (8.7) | 0.36% | — | Radiflow Isap Smart CollectorAICentos 7AI | 9/7/2025 | 17/6/2026 | The Linux distribution underlying the Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) is obsolete and reached end of life (EOL) on June 30, 2024. Thus, any unmitigated vulnerability could be exploited to affect this product. | |
| Aplazada | Media (6.8) | 0.29% | — | Radiflow Isap Smart CollectorAI | 9/7/2025 | 17/6/2026 | The Linux deprivileged user vpuser in Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) can read the entire file system content, including files belonging to other users and having restricted access (like, for example, the root password hash). | |
| Analizada | Media (6.1) | 0.22% | — | SAP Basis | 8/7/2025 | 17/6/2026 | SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to create a malicious link which they can make publicly available. When an authenticated victim clicks on this malicious link, injected input data will be used by the web site page generation to create content which when… | |
| Aplazada | Media (6.9) | 0.15% | — | SapcarAI | 8/7/2025 | 17/6/2026 | SAPCAR allows an attacker logged in with high privileges to override the permissions of the current and parent directories of the user or process extracting the archive, leading to privilege escalation. On successful exploitation, an attacker could modify the critical files by tampering with signed archives without… | |
| Aplazada | Media (6.9) | 0.13% | — | SapcarAI | 8/7/2025 | 17/6/2026 | SAPCAR allows an attacker logged in with high privileges to create a malicious SAR archive in SAPCAR. This could enable the attacker to exploit critical files and directory permissions without breaking signature validation, resulting in potential privilege escalation. This has high impact on integrity, but low impact… | |
| Analizada | Media (4.3) | 0.23% | — | SAP Basis | 8/7/2025 | 17/6/2026 | Due to a missing authorization check in an obsolete RFC enabled function module in SAP BASIS, an authenticated low-privileged attacker could call a Remote Function Call (RFC), potentially accessing restricted system information. This results in low impact on confidentiality, with no impact on integrity or availability… | |
| Aplazada | Media (6.1) | 0.25% | — | SAP Businessobjects Content Administrator WorkbenchAI | 8/7/2025 | 17/6/2026 | Due to insufficient sanitization in the SAP BusinessObjects Content Administrator Workbench, attackers could craft malicious URLs and execute scripts in a victim�s browser. This could potentially lead to the exposure or modification of web client data, resulting in low impact on confidentiality and integrity, with no… | |
| Aplazada | Media (6.1) | 0.23% | — | SAP Netweaver Application Server AbapAI | 8/7/2025 | 17/6/2026 | Due to an open redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft a URL link embedding a malicious script at a location not properly sanitized. When a victim clicks on this link, the script executes within the victim's browser, redirecting them to a site controlled… | |
| Aplazada | Crítica (9.1) | 0.76% | — | SAP Netweaver Enterprise PortalAI | 8/7/2025 | 17/6/2026 | SAP NetWeaver Enterprise Portal Federated Portal Network is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system. | |
| Aplazada | Media (5.6) | 0.14% | — | GuixtAISAP GUI FOR WindowsAI | 8/7/2025 | 17/6/2026 | The GuiXT application, which is integrated with SAP GUI for Windows, uses obfuscation algorithms instead of secure symmetric ciphers for storing the credentials of an RFC user on the client PC. This leads to a high impact on confidentiality because any attacker who gains access to the user hive of this user�s windows… | |
| Aplazada | Baja (3.5) | 0.14% | — | SAP Netweaver Application Server JavaAI | 8/7/2025 | 17/6/2026 | The widely used component that establishes outbound TLS connections in SAP NetWeaver Application Server Java does not reliably match the hostname that is used for the connection against the wildcard hostname defined in the received certificate of remote TLS server. This might lead to the outbound connection being… | |
| Aplazada | Media (5.4) | 0.19% | — | SAP Data Services Management ConsoleAI | 8/7/2025 | 17/6/2026 | Due to a Cross-Site Scripting vulnerability in SAP Data Services Management Console, an authenticated attacker could exploit the search functionality associated with DQ job status reports. By intercepting requests, malicious script can be injected and subsequently executed when a user loads the affected page. This… |