Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
39 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.65% | — | SAP Fiori Launchpad (news Tile Application) | 13/11/2020 | 17/6/2026 | SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to use SAP Fiori Launchpad News tile Application to send malicious code, to a different end user (victim), because News tile does not sufficiently encode user controlled inputs, resulting in Reflected… | |
| Modificada | Alta (8.6) | 1.4% | — | SAP Fiori Launchpad (news Tile Application) | 10/11/2020 | 17/6/2026 | SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send a crafted request to a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network to retrieve… | |
| Modificada | Media (6.1) | 0.68% | — | SAP Fiori Launchpad | 9/9/2020 | 17/6/2026 | SAP Fiori Launchpad does not sufficiently encode user controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, resulting in reflected Cross-Site Scripting (XSS) vulnerability. With a successful attack, the attacker can steal authentication… | |
| Modificada | Media (4.3) | 0.56% | — | SAP S/4 Hana Fiori UI FOR General Ledger Accounting | 12/8/2020 | 17/6/2026 | SAP S/4 HANA (Fiori UI for General Ledger Accounting), versions 103, 104, does not perform necessary authorization checks for an authenticated user working with attachment service, allowing the attacker to delete attachments due to Missing Authorization Check. | |
| Modificada | Media (5.4) | 0.61% | — | SAP Fiori | 10/6/2020 | 17/6/2026 | SAP Fiori for SAP S/4HANA, versions - 100, 200, 300, 400, allows an attacker to redirect users to a malicious site due to insufficient URL validation, leading to URL Redirection. | |
| Modificada | Media (6.1) | 0.65% | — | SAP Fiori Launchpad | 10/3/2020 | 17/6/2026 | SAP Fiori Launchpad, versions- 753, 754, does not sufficiently encode user-controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, leading to reflected Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Alta (7.8) | 0.79% | — | SAP Fiori Client | 13/11/2018 | 17/6/2026 | When opening a deep link URL in SAP Fiori Client with log level set to "Debug", the client application logs the URL to the log file. If this URL contains malicious JavaScript code it can eventually run inside the built-in log viewer of the application in case user opens the viewer and taps on the hyperlink in the… | |
| Modificada | Alta (7.8) | 0.75% | — | SAP Fiori Client | 13/11/2018 | 17/6/2026 | The broadcast messages received by SAP Fiori Client are not protected by permissions. SAP Fiori Client version 1.11.5 in Google Play store addresses these issues and users must update to that version. | |
| Modificada | Alta (7.8) | 0.87% | — | SAP Fiori Client | 13/11/2018 | 17/6/2026 | Locally, without any permission, an arbitrary android application could delete the SSO configuration of SAP Fiori Client. SAP Fiori Client version 1.11.5 in Google Play store addresses these issues and users must update to that version. | |
| Modificada | Alta (7.8) | 0.79% | — | SAP Fiori Client | 13/11/2018 | 17/6/2026 | It is possible for a malware application installed on an Android device to send local push notifications with an empty message to SAP Fiori Client and cause the application to crash. SAP Fiori Client version 1.11.5 in Google Play store addresses these issues and users must update to that version. | |
| Modificada | Alta (7.7) | 1.2% | — | SAP Fiori Client | 13/11/2018 | 17/6/2026 | It is possible for a malicious application or malware to execute JavaScript in a SAP Fiori application. This can include reading and writing of information and calling device specific JavaScript APIs in the application. SAP Fiori Client version 1.11.5 in Google Play store addresses these issues and users must update… | |
| Modificada | Media (6.5) | 0.67% | — | SAP Fiori | 9/10/2018 | 17/6/2026 | SAP Fiori 1.0 for SAP ERP HCM (Approve Leave Request, version 2) application allows an attacker to trick an authenticated user to send unintended request to the web server. This vulnerability is due to insufficient CSRF protection. | |
| Modificada | Media (5) | 2.7% | 💥 Exploit | Ermenegildo Fiorito Irmin CMS | 8/4/2010 | 16/6/2026 | Directory traversal vulnerability in Irmin CMS (formerly Pepsi CMS) 0.6 BETA2 allows remote attackers to read arbitrary files via a .. (dot dot) in the w parameter to index.php. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Ermenegildo Fiorito Irmin CMS | 7/4/2010 | 16/6/2026 | Directory traversal vulnerability in includes/template-loader.php in Irmin CMS (formerly Pepsi CMS) 0.5 and 0.6 BETA2, when register_globals is enabled, allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the _Root_Path parameter. NOTE: some of these details are obtained from third… |