Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

2261 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)8.8%💥 PoCSamba RsyncRedhat OpenshiftRedhat Openshift Container PlatformRedhat Enterprise Linux+1814/1/202521/9/2026
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.
AplazadaCrítica (9.9)0.70%—SAP Netweaver Application Server FOR AbapAISAP Abap PlatformAI14/1/202517/6/2026
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate access to the system by exploiting improper authentication checks, resulting in privilege escalation. On successful exploitation, this can result in potential security concerns. This results in a high…
AplazadaAlta (7.8)0.18%—SapsetupAI14/1/202517/6/2026
Due to DLL injection vulnerability in SAPSetup, an attacker with either local user privileges or with access to a compromised corporate user�s Windows account could gain higher privileges. With this, he could move laterally within the network and further compromise the active directory of a company. This leads to high…
AplazadaMedia (4.3)0.27%—SAP Netweaver Application Server AbapAI14/1/202517/6/2026
An obsolete functionality in SAP NetWeaver Application Server ABAP did not perform necessary authorization checks. Because of this, an authenticated attacker could obtain information that would otherwise be restricted. It has no impact on integrity or availability on the application.
AplazadaMedia (6.3)0.26%—SAP Netweaver Application Server JavaAI14/1/202517/6/2026
Due to a missing authorization check on service endpoints in the SAP NetWeaver Application Server Java, an attacker with standard user role can create JCo connection entries, which are used for remote function calls from or to the application server. This could lead to low impact on confidentiality, integrity, and…
AnalizadaAlta (8.8)0.58%—SAP Basis14/1/202517/6/2026
Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted information due to weak access controls. This can have a significant impact on the confidentiality, integrity, and availability of an application
AnalizadaAlta (8.8)0.74%—SAP Basis14/1/202517/6/2026
SAP NetWeaver AS ABAP and ABAP Platform does not check for authorization when a user executes some RFC function modules. This could lead to an attacker with basic user privileges to gain control over the data in Informix database, leading to complete compromise of confidentiality, integrity and availability.
AnalizadaCrítica (9.1)0.51%—SAP Businessobjects Business Intelligence Platform14/1/202517/6/2026
SAP BusinessObjects Business Intelligence Platform allows an unauthenticated attacker to perform session hijacking over the network without any user interaction, due to an information disclosure vulnerability. Attacker can access and modify all the data of the application.
AnalizadaMedia (6.5)0.40%—SAP Businessobjects Business Intelligence Platform14/1/202517/6/2026
SAP BusinessObjects Business Intelligence Platform allows an authenticated user with restricted access to inject malicious JS code which can read sensitive information from the server and send it to the attacker. The attacker could further use this information to impersonate as a high privileged user causing high…
AplazadaMedia (6)0.18%—SAP Netweaver Application Server AbapAISAP GUI FOR HtmlAI14/1/202517/6/2026
Applications based on SAP GUI for HTML in SAP NetWeaver Application Server ABAP store user input in the local browser storage to improve usability. An attacker with administrative privileges or access to the victim�s user directory on the Operating System level would be able to read this data. Depending on the user…
AnalizadaMedia (6.5)0.34%—SAP Basis14/1/202517/6/2026
In SAP Business Workflow and SAP Flexible Workflow, an authenticated attacker can manipulate a parameter in an otherwise legitimate resource request to view sensitive information that should otherwise be restricted. The attacker does not have the ability to modify the information or to make the information unavailable.
AplazadaMedia (4.8)0.24%—SAP Netweaver AS JavaAI14/1/202517/6/2026
SAP NetWeaver AS JAVA (User Admin Application) is vulnerable to stored cross site scripting vulnerability. An attacker posing as an admin can upload a photo with malicious JS content. When a victim visits the vulnerable component, the attacker can read and modify information within the scope of victim's web browser.
AplazadaMedia (6)0.20%—SAP GUI FOR JavaAI14/1/202517/6/2026
SAP GUI for Java saves user input on the client PC to improve usability. An attacker with administrative privileges or access to the victim�s user directory on the Operating System level would be able to read this data. Depending on the user input provided in transactions, the disclosed data could range from…
AplazadaMedia (6)0.24%—SAP GUI FOR WindowsAI14/1/202517/6/2026
SAP GUI for Windows stores user input on the client PC to improve usability. Under very specific circumstances an attacker with administrative privileges or access to the victim�s user directory on the Operating System level would be able to read this data. Depending on the user input provided in transactions, the…
AnalizadaMedia (5.3)0.34%—SAP Basis14/1/202517/6/2026
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to gain unauthorized access to system information. By using a specific URL parameter, an unauthenticated attacker could retrieve details such as system configuration. This has a limited impact on the confidentiality of the application and…
AplazadaMedia (6.1)0.35%—Whatsapp Click TO ChatAI9/1/202517/6/2026
The WhatsApp 🚀 click to chat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'manycontacts_code' parameter in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaAlta (8.5)0.60%—SAP Netweaver Application Server AbapAI10/12/202417/6/2026
In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, which can be used to expose credentials for a remote service. These credentials can then be further exploited to completely compromise the remote…
AplazadaAlta (7.2)0.27%—SAP Netweaver AdministratorAI10/12/202417/6/2026
SAP NetWeaver Administrator(System Overview) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in Server-Side Request Forgery (SSRF) which could have a low impact on integrity and…
AplazadaMedia (4.3)0.27%—SAP Netweaver Application Server FOR AbapAISAP Abap PlatformAI10/12/202417/6/2026
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to gain higher access levels than they should have by exploiting improper authorization checks, resulting in privilege escalation. While authorizations for import and export are distinguished, a single authorization is applied…
AplazadaMedia (4.3)0.26%—SAP HCM Approve TimesheetsAI10/12/202417/6/2026
SAP HCM Approve Timesheets Version 4 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.There is low impact on integrity of the application. Confidentiality and availibility are not impacted.
AplazadaBaja (2.7)0.20%—SAP Commerce CloudAI10/12/202417/6/2026
Webservice API endpoints for Assisted Service Module within SAP Commerce Cloud has information disclosure vulnerability. When an authorized agent searches for customer to manage their accounts, the request url includes customer data and it is recorded in server logs. If an attacker impersonating as authorized admin…
AplazadaBaja (3.3)0.19%—SAP Product Lifecycle Costing ClientAI10/12/202417/6/2026
SAP Product Lifecycle Costing Client (versions below 4.7.1) application loads on demand a DLL that is available with Windows OS. This DLL is loaded from the computer running SAP Product Lifecycle Costing Client application. That particular DLL could be replaced by a malicious one, that could execute commands as being…
AnalizadaMedia (5.3)0.32%—SAP Businessobjects Business Intelligence Platform10/12/202417/6/2026
Under certain conditions SAP BusinessObjects Business Intelligence platform allows an attacker to access information which would otherwise be restricted.This has low impact on Confidentiality with no impact on Integrity and Availability of the application.
AnalizadaAlta (7.1)0.15%—SAP Host Agent12/11/202417/6/2026
An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access. On successful exploitation the attacker could cause high impact on confidentiality and integrity of the application.
AplazadaMedia (4.3)0.38%—SAP Netweaver Application Server AbapAISAP WEB DispatcherAISAP GUI FOR HtmlAI12/11/202417/6/2026
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the server, which otherwise would be restricted.This attack is possible only if a Web Dispatcher or some sort of Proxy Server is in use and the file in question was previously opened or downloaded in an…