Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2261 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.42% | — | SAP Supplier Relationship Management | 13/5/2025 | 17/6/2026 | The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an application servlet request with a crafted XML file which when parsed, enables the attacker to access sensitive files and data. This vulnerability has a high impact on the application's… | |
| Analizada | Crítica (9.8) | 0.77% | — | SAP Supplier Relationship Management | 13/5/2025 | 17/6/2026 | The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component, which allows an unauthenticated attacker to send malicious payload request in a specific encoding format. The servlet will then decode this malicious request which will result in deserialization of data in… | |
| Analizada | Media (5.3) | 0.37% | — | SAP Supplier Relationship Management | 13/5/2025 | 17/6/2026 | The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to send an malicious request to the application, which could disclose the internal version details of the affected system. This… | |
| Analizada | Media (6.1) | 0.29% | — | SAP Supplier Relationship Management | 13/5/2025 | 17/6/2026 | The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to craft a malicious link, which when clicked by a victim, redirects the browser to a malicious site. On successful exploitation, the… | |
| Analizada | Media (6.1) | 0.29% | — | SAP Supplier Relationship Management | 13/5/2025 | 17/6/2026 | he Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to execute malicious script in the victim�s browser. This vulnerability has low impact on confidentiality and integrity within the… | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | SAP Netweaver | 24/4/2025 | 4/8/2026 | SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted… | |
| Aplazada | Media (4.6) | 0.14% | — | SAP Learning SolutionAI | 22/4/2025 | 17/6/2026 | SAP Learning Solution is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to trick authenticated user into sending unintended requests to the server. GET-based OData function is named in a way that it violates the expected behaviour. This issue could impact both the confidentiality and integrity… | |
| Aplazada | Media (4.3) | 0.27% | — | SAP Field Logistics Manage LogisticsAI | 22/4/2025 | 17/6/2026 | SAP Field Logistics Manage Logistics application OData meta-data property is vulnerable to data tampering, due to which certain fields could be externally modified by an attacker causing low impact on integrity of the application. Confidentiality and availability are not impacted. | |
| Analizada | Crítica (9.8) | 0.64% | — | Wallosapp Wallos | 16/4/2025 | 17/6/2026 | Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to restore database by uploading a ZIP file. The contents of the ZIP file are extracted on the server. This functionality enables an unauthenticated attacker to upload malicious files to the server.… | |
| Analizada | Crítica (9.8) | 0.62% | — | Wallosapp Wallos | 16/4/2025 | 17/6/2026 | Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to restore backups by uploading a ZIP file. The contents of the ZIP file are extracted on the server. This functionality enables an authenticated attacker (being an administrator is not required) to upload… | |
| Aplazada | Media (4.3) | 0.29% | — | SAP S4coreAI | 8/4/2025 | 17/6/2026 | SAP S4CORE OData meta-data property is vulnerable to data tampering, due to which entity set could be externally modified by an attacker causing low impact on integrity of the application. Confidentiality and availability is not impacted. | |
| Analizada | Alta (7.1) | 0.15% | — | SAP Businessobjects Business Intelligence Platform | 8/4/2025 | 17/6/2026 | Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker who has local access to the system could modify files potentially disrupting operations or cause service downtime hence leading to a high impact on integrity and availability. However, this vulnerability does not… | |
| Aplazada | Media (4.3) | 0.35% | — | SAP NetweaverAI | 8/4/2025 | 17/6/2026 | SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would normally require additional validation. Once logged into the ABAP system, the attacker can run a specific transaction that exposes sensitive system code without proper authorization. This… | |
| Aplazada | Crítica (9.9) | 0.74% | — | SAP Landscape TransformationAI | 8/4/2025 | 17/6/2026 | SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor,… | |
| Aplazada | Media (4.4) | 0.15% | — | SAP Solution ManagerAI | 8/4/2025 | 17/6/2026 | Due to a missing authorization check, an authenticated attacker could upload a file as a template for solution documentation in SAP Solution Manager 7.1. After successful exploitation, an attacker can cause limited impact on the integrity and availability of the application. | |
| Aplazada | Crítica (9.8) | 0.60% | — | SAP Financial ConsolidationAI | 8/4/2025 | 17/6/2026 | SAP Financial Consolidation allows an unauthenticated attacker to gain unauthorized access to the Admin account. The vulnerability arises due to improper authentication mechanisms, due to which there is high impact on the Confidentiality, Integrity & Availability of the application. | |
| Aplazada | Media (4.1) | 0.26% | — | SAP NetweaverAISAP Abap PlatformAI | 8/4/2025 | 17/6/2026 | Due to incorrect memory address handling in ABAP SQL of SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker with high privileges could execute certain forms of SQL queries leading to manipulation of content in the output variable. This vulnerability has a low impact on the… | |
| Aplazada | Alta (7.7) | 0.78% | — | SAP Capital Yield TAX ManagementAI | 8/4/2025 | 17/6/2026 | SAP Capital Yield Tax Management has directory traversal vulnerability due to insufficient path validation. This could allow an attacker with low privileges to read files from directory which they don�t have access to, hence causing a high impact on confidentiality. Integrity and Availability are not affected. | |
| Aplazada | Media (6.7) | 0.79% | — | SAP ERP BW Business ContentAI | 8/4/2025 | 17/6/2026 | SAP ERP BW Business Content is vulnerable to OS Command Injection through certain function modules. These function modules, when executed with elevated privileges, improperly handle user input, allowing attacker to inject arbitrary OS commands. This vulnerability allows the execution of unintended commands on the… | |
| Aplazada | Media (4.3) | 0.27% | — | SAP Netweaver Application Server AbapAI | 8/4/2025 | 17/6/2026 | A Missing Authorization Check vulnerability exists in the Virus Scanner Interface of SAP NetWeaver Application Server ABAP. Because of this, an attacker authenticated as a non-administrative user can initiate a transaction, allowing them to access but not modify non-sensitive data without further authorization and… | |
| Aplazada | Media (4.2) | 0.23% | — | SAP CommerceAI | 8/4/2025 | 17/6/2026 | Under specific conditions and prerequisites, an unauthenticated attacker could access customer coupon codes exposed in the URL parameters of the Coupon Campaign URL in SAP Commerce. This could allow the attacker to use the disclosed coupon code, hence posing a low impact on confidentiality and integrity of the… | |
| Aplazada | Crítica (9.9) | 0.78% | — | SAP S/4hanaAI | 8/4/2025 | 17/6/2026 | SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full… | |
| Aplazada | Alta (7.7) | 0.59% | — | SAP Solution ManagerAI | 8/4/2025 | 17/6/2026 | Due to directory traversal vulnerability, an authorized attacker could gain access to some critical information by using RFC enabled function module. Upon successful exploitation, they could read files from any managed system connected to SAP Solution Manager, leading to high impact on confidentiality. There is no… | |
| Aplazada | Media (5.3) | 0.32% | — | SAP KMC WPCAI | 8/4/2025 | 17/6/2026 | SAP KMC WPC allows an unauthenticated attacker to remotely retrieve usernames by a simple parameter query which could expose sensitive information causing low impact on confidentiality of the application. This has no effect on integrity and availability. | |
| Aplazada | Media (6.8) | 0.17% | — | SAP Commerce CloudAI | 8/4/2025 | 17/6/2026 | SAP Commerce Cloud (Public Cloud) does not allow to disable unencrypted HTTP (port 80) entirely, but instead allows a redirect from port 80 to 443 (HTTPS). As a result, Commerce normally communicates securely over HTTPS. However, the confidentiality and integrity of data sent on the first request before the redirect… |