Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
2261 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.7) | 0.28% | — | SAP Businessobjects Business Intelligence PlatformAI | 11/3/2025 | 17/6/2026 | SAP BusinessObjects Business Intelligence Platform allows an attacker to inject JavaScript code in Web Intelligence reports. This code is then executed in the victim's browser each time the vulnerable page is visited by the victim. On successful exploitation, an attacker could cause limited impact on confidentiality… | |
| Aplazada | Media (4.7) | 0.30% | — | Ataksapp Reservation Management SystemAI | 6/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AtaksAPP Reservation Management System allows Cross-Site Scripting (XSS). This issue affects Reservation Management System: before 4.2.3. | |
| Aplazada | Media (6.9) | 0.57% | — | Pixsoft E-saphiraAI | 2/3/2025 | 17/6/2026 | A vulnerability has been found in Pixsoft E-Saphira 1.7.24 and classified as critical. This vulnerability affects unknown code of the file /servlet?act=login&tipo=1 of the component Login Endpoint. The manipulation of the argument txtUsuario leads to sql injection. The attack can be initiated remotely. The exploit has… | |
| Analizada | Alta (7.8) | 0.16% | — | Mongodb MongoshRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder FOR Arm64 EUSRedhat Codeready Linux Builder FOR IBM Z Systems EUS+9 | 27/2/2025 | 17/6/2026 | mongosh may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privilege, when a crafted file is stored in C:\node_modules\. This issue affects mongosh prior to 2.3.0 | |
| Analizada | Alta (7.8) | 0.15% | — | Mongodb CompassRedhat Enterprise Linux FOR ARM 64Redhat Enterprise Linux FOR IBM Z SystemsRedhat Enterprise Linux Server FOR Power Little Endian Update Services FOR SAP Solutions+1 | 27/2/2025 | 17/6/2026 | MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1 | |
| Modificada | Media (5.4) | 0.30% | — | Homeasap Easy MLS Listings Import | 18/2/2025 | 17/6/2026 | The Easy MLS Listings Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'homeasap-featured-listings' shortcode in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Alta (8.6) | 0.70% | — | SAP Supplier Relationship ManagementAI | 11/2/2025 | 17/6/2026 | SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a publicly available servlet to download an arbitrary file over the network without any user interaction. This can reveal highly sensitive information with no impact to integrity or availability. | |
| Aplazada | Alta (8.1) | 0.50% | — | SAP ApprouterAI | 11/2/2025 | 17/6/2026 | The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an authorization code an attacker can steal the session of the victim by injecting malicious payload causing High impact on confidentiality and integrity of the application | |
| Aplazada | Media (6.8) | 0.18% | — | SAP CommerceAI | 11/2/2025 | 17/6/2026 | SAP Commerce, by default, sets certain cookies with the SameSite attribute configured to None (SameSite=None). This includes authentication cookies utilized in SAP Commerce Backoffice. Applying this setting reduces defense in depth against CSRF and may lead to future compatibility issues. | |
| Aplazada | Media (6.8) | 0.32% | — | SAP CommerceAI | 11/2/2025 | 17/6/2026 | SAP Commerce (Backoffice) uses the deprecated X-FRAME-OPTIONS header to protect against clickjacking. While this protection remains effective now, it may not be the case in the future as browsers might discontinue support for this header in favor of the frame-ancestors CSP directive. Hence, clickjacking could become… | |
| Aplazada | Media (4.3) | 0.26% | — | SAP Abap PlatformAI | 11/2/2025 | 17/6/2026 | The ABAP Build Framework in SAP ABAP Platform allows an authenticated attacker to gain unauthorized access to a specific transaction. By executing the add-on build functionality within the ABAP Build Framework, an attacker could call the transaction and view its details. This has a limited impact on the… | |
| Aplazada | Media (6) | 0.17% | — | SAP GUI FOR WindowsAISAP RFC ServiceAI | 11/2/2025 | 17/6/2026 | SAP GUI for Windows & RFC service credentials are incorrectly stored in the memory of the program allowing an unauthenticated attacker to access information within systems, resulting in privilege escalation. On successful exploitation, this could result in disclosure of highly sensitive information. This has no impact… | |
| Aplazada | Media (4.3) | 0.26% | — | SAP Netweaver Application Server JavaAI | 11/2/2025 | 17/6/2026 | SAP NetWeaver Application Server Java allows an attacker to access an endpoint that can disclose information about deployed server components, including their XML definitions. This information should ideally be restricted to customer administrators, even though they may not need it. These XML files are not entirely… | |
| Aplazada | Alta (7.1) | 0.25% | — | SAP Hana XS Advanced ModelAI | 11/2/2025 | 17/6/2026 | The User Account and Authentication service (UAA) for SAP HANA extended application services, advanced model (SAP HANA XS advanced model) allows an unauthenticated attacker to craft a malicious link, that, when clicked by a victim, redirects the browser to a malicious site due to insufficient redirect URL validation.… | |
| Aplazada | Media (6.1) | 0.26% | — | SAP Businessobjects PlatformAI | 11/2/2025 | 17/6/2026 | SAP BusinessObjects Platform (BI Launchpad) does not sufficiently handle user input, resulting in Cross-Site Scripting (XSS) vulnerability. The application allows an unauthenticated attacker to craft a URL that embeds a malicious script within an unprotected parameter. When a victim clicks the link, the script will be… | |
| Analizada | Alta (7.5) | 0.35% | — | SAP Basis | 11/2/2025 | 17/6/2026 | SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respond differently based on the existence of a specified user, potentially revealing sensitive information. This issue does not enable data modification and has no impact on server availability. | |
| Aplazada | Baja (3.1) | 0.25% | — | SAP FioriAISAP ERPAISAP OdataAI | 11/2/2025 | 17/6/2026 | Cached values belonging to the SAP OData endpoint in SAP Fiori for SAP ERP could be poisoned by modifying the Host header value in an HTTP GET request. An attacker could alter the `atom:link` values in the returned metadata redirecting them from the SAP server to a malicious link set by the attacker. Successful… | |
| Aplazada | Media (4.3) | 0.24% | — | SAP SdccnAI | 11/2/2025 | 17/6/2026 | Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an authenticated attacker could generate technical meta-data. This leads to a low impact on integrity. There is no impact on confidentiality or availability | |
| Aplazada | Media (5.3) | 0.29% | — | SAP SdccnAI | 11/2/2025 | 17/6/2026 | Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an unauthenticated attacker could generate technical meta-data. This leads to a low impact on integrity. There is no impact on confidentiality or availability. | |
| Analizada | Media (6.5) | 0.38% | — | SAP Businessobjects Business Intelligence Platform | 11/2/2025 | 17/6/2026 | Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intelligence platform allows an attacker with admin rights to generate or retrieve a secret passphrase, enabling them to impersonate any user in the system. This results in a high impact on confidentiality and integrity, with… | |
| Aplazada | Media (5.4) | 0.27% | 💥 PoC | SAP Netweaver Application Server JavaAI | 11/2/2025 | 17/6/2026 | SAP NetWeaver Application Server Java does not sufficiently handle user input, resulting in a stored cross-site scripting vulnerability. The application allows attackers with basic user privileges to store a Javascript payload on the server, which could be later executed in the victim's web browser. With this the… | |
| Aplazada | Alta (7.1) | 0.17% | — | Rishi ON Page SEO Whatsapp Chat ButtonAI | 7/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rishi On Page SEO + Whatsapp Chat Button ops-robots-txt allows Stored XSS.This issue affects On Page SEO + Whatsapp Chat Button: from n/a through <= 2.0.0. | |
| Analizada | Media (6.1) | 0.45% | — | Wallosapp Wallos | 23/1/2025 | 17/6/2026 | Cross Site Scripting vulnerability in Wallos v.2.41.0 allows a remote attacker to execute arbitrary code via the profile picture function. | |
| Modificada | Alta (7.5) | 4.7% | — | Samba RsyncRedhat DiscoveryRedhat Openshift Container PlatformRedhat Enterprise Linux+16 | 14/1/2025 | 30/6/2026 | A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory. | |
| Modificada | Alta (7.5) | 2.3% | — | Samba RsyncAlmalinuxArchlinux Arch LinuxGentoo Linux+14 | 14/1/2025 | 30/6/2026 | A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification… |