Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

2261 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4)0.15%—SapcarAI8/7/202517/6/2026
A memory corruption vulnerability exists in SAPCAR allowing an attacker to craft malicious SAPCAR archives. When a high privileged victim extracts this malicious archive, it gets processed by SAPCAR on their system, resulting in out-of-bounds memory read and write. This could lead to file extraction and file overwrite…
AplazadaMedia (5.8)0.29%—SapcarAI8/7/202517/6/2026
SAPCAR improperly sanitizes the file paths while extracting SAPCAR archives. Due to this, an attacker could craft a malicious SAPCAR archive containing directory traversal sequences. When a high privileged victim extracts this malicious archive, it is then processed by SAPCAR on their system, causing files to be…
AplazadaMedia (6.1)0.23%—SAP Netweaver Application Server AbapAISAP Abap PlatformAI8/7/202517/6/2026
SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject a malicious script into a dynamically crafted URL. The victim, when tricked into clicking on this crafted URL unknowingly executes the malicious payload in their browser. On successful exploitation, the attacker can…
AnalizadaMedia (4.3)0.26%—SAP Netweaver8/7/202517/6/2026
SAP NetWeaver allows an authenticated non-administrative user to call the remote-enabled function module which could grants access to non-sensitive information about the SAP system and OS without requiring any specific knowledge or controlled conditions. This leads to a low impact on confidentiality with no effect on…
AplazadaCrítica (9.9)0.98%—SAP S/4hanaAISAP SCMAI8/7/202517/6/2026
SAP S/4HANA and SAP SCM Characteristic Propagation has remote code execution vulnerability. This allows an attacker with user level privileges to create a new report with his own code potentially gaining full control of the affected SAP system causing high impact on confidentiality, integrity, and availability of the…
AplazadaCrítica (9.1)0.72%—SAP NetweaverAI8/7/202517/6/2026
SAP NetWeaver XML Data Archiving Service allows an authenticated attacker with administrative privileges to exploit an insecure Java deserialization vulnerability by sending a specially crafted serialized Java object. This could lead to high impact on confidentiality, integrity, and availability of the application.
AplazadaMedia (4.1)0.25%—SAP CMC Promotion ManagementAI8/7/202517/6/2026
SAP CMC Promotion Management allows an authenticated attacker to enumerate internal network systems by submitting crafted requests during job source configuration. By analysing response times for various IP addresses and ports, the attacker can infer valid network endpoints. Successful exploitation may lead to…
AplazadaCrítica (9.1)0.72%—SAP Netweaver Enterprise PortalAI8/7/202517/6/2026
SAP NetWeaver Enterprise Portal Administration is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.
AplazadaCrítica (9.1)0.74%—SAP Netweaver Application Server FOR JavaAI8/7/202517/6/2026
A critical vulnerability in SAP NetWeaver Application server for Java Log Viewer enables authenticated administrator users to exploit unsafe Java object deserialization. Successful exploitation can lead to full operating system compromise, granting attackers complete control over the affected system. This results in a…
AplazadaMedia (6.1)0.24%—SAP Business WarehouseAI8/7/202517/6/2026
SAP Business Warehouse (Business Explorer Web) allows an attacker to create a malicious link. If an authenticated user clicks on this link, the injected script gets executed within the scope of victim�s browser. This potentially leads to an impact on confidentiality and integrity. Availability is not impacted.
AplazadaMedia (4.9)0.33%—SAP Netweaver Application Server FOR AbapAI8/7/202517/6/2026
Due to a missing authorization check in SAP NetWeaver Application server for ABAP, an authenticated user with high privileges could exploit the insufficient validation of user permissions to access sensitive database tables. By leveraging overly permissive access configurations, unauthorized reading of critical data…
AplazadaMedia (4.3)0.22%—SAP Business WarehouseAISAP Bw/4hanaAI8/7/202517/6/2026
SAP Business Warehouse and SAP BW/4HANA BEx Tools allow an authenticated attacker to gain higher access levels than intended by exploiting improper authorization checks. This could potentially impact data integrity by allowing deletion of user table entries.�It has no impact on the confidentiality and availability of…
AplazadaBaja (2.7)0.43%—SAP Netweaver Business WarehouseAISAP CcawAI8/7/202517/6/2026
SAP NetWeaver Business Warehouse CCAW application allows a privileged attacker to cause a high CPU load by executing a RFC enabled function modules without any input parameters, which results in reduced performance or interrupted operation of the affected resource. This leads to low impact on availability of the…
AplazadaAlta (8.1)0.47%—SAP NetweaverAI8/7/202517/6/2026
SAP Netweaver System Configuration does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This could completely compromise the integrity and availability with no impact on confidentiality of the system.
AplazadaAlta (7.7)0.41%—SAP Business WarehouseAISAP Plug-in BasisAI8/7/202517/6/2026
SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to add fields to arbitrary SAP database tables and/or structures, potentially rendering the system unusable. On successful exploitation, an attacker can render the system unusable by triggering short dumps on login. This could cause a high…
AplazadaMedia (4.1)0.26%—SAP Businessobjects Business Intelligence PlatformAISAP WEB IntelligenceAI8/7/202517/6/2026
SAP�BusinessObjects Business�Intelligence Platform (Web Intelligence) is vulnerable to HTML Injection, allowing an attacker with basic user privileges to inject malicious code into specific input fields. This could lead to unintended redirects or manipulation of application behavior, such as redirecting users to…
AnalizadaAlta (7.8)55%⚠ Explotación activa💥 ExploitSudo Project SudoCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+430/6/202517/6/2026
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
AplazadaMedia (5.5)0.50%💥 PoCEsapi-java-legacyAI29/6/202517/6/2026
A vulnerability was found in ESAPI esapi-java-legacy and classified as problematic. This issue affects the interface Encoder.encodeForSQL of the SQL Injection Defense. An attack leads to an improper neutralization of special elements. The attack may be initiated remotely and an exploit has been disclosed to the…
AplazadaCrítica (9.3)0.64%—Sapido Wireless RouterAI24/6/202517/6/2026
Multiple wireless router models from Sapido have an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to directly access a system configuration file and obtain plaintext administrator credentials. The affected models are out of support; replacing the device is recommended.
AplazadaCrítica (9.3)1.7%—Sapido Wireless RouterAI24/6/202517/6/2026
Multiple wireless router models from Sapido have an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. The affected models are out of support; replacing the device is recommended.
AplazadaAlta (8.1)0.58%—Thembay SapaAI17/6/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Sapa sapa allows PHP Local File Inclusion.This issue affects Sapa: from n/a through <= 1.1.14.
ModificadaAlta (7.5)1.4%—Xmlsoft Libxml2Redhat Jboss Core ServicesRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR Arm64+1612/6/202518/9/2026
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
AplazadaMedia (5.3)0.19%—SAP Business ONE Integration FrameworkAI10/6/202517/6/2026
The security settings in the SAP Business One Integration Framework are not adequately checked, allowing attackers to bypass the 403 Forbidden error and access restricted pages. This leads to low impact on confidentiality of the application, there is no impact on integrity and availability.
AplazadaMedia (5.6)0.24%—SAP MDM ServerAI10/6/202517/6/2026
SAP MDM Server allows an attacker to gain control of existing client sessions and execute certain functions without having to re-authenticate giving the ability to access or modify non-sensitive information or consume sufficient resources which could degrade the performance of the server causing low impact on…
AplazadaAlta (7.5)0.41%—SAP MDM ServerAI10/6/202517/6/2026
SAP MDM Server Read function allows an attacker to send specially crafted packets which could trigger a memory read access violation in the server process that would then fail and exit unexpectedly causing high impact on availability with no impact on confidentiality and integrity of the application.