Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
2261 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.53% | — | Wallosapp WallosAI | 31/8/2026 | 8/9/2026 | Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before version 4.9.6, Wallos's OIDC login links an incoming OIDC identity to an existing local account by matching the email claim alone, without verifying that the IdP marked that email as verified (email_verified). When… | |
| Aplazada | Alta (8.5) | 0.54% | — | Wallosapp WallosAI | 31/8/2026 | 8/9/2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, Admin-configured OIDC token_url and user_info_url in includes/oidc/handle_oidc_callback.php:18-49 are used directly in curl_init() with zero SSRF filtering. Unlike logo/webhook URLs which have… | |
| Aplazada | Alta (8.5) | 0.51% | — | Wallosapp WallosAI | 31/8/2026 | 8/9/2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/db/restore.php calls ZipArchive::extractTo() without validating entry names for ../ sequences. Admin uploads crafted zip with entry logos/../../endpoints/shell.php to write webshell to webroot. Extension… | |
| Aplazada | Alta (8.2) | 0.50% | — | Wallosapp WallosAI | 31/8/2026 | 8/9/2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/notifications/testemailnotifications.php accepts smtpaddress and smtpport from POST body with zero SSRF validation. PHPMailer connects to attacker-supplied host:port. Every other notification endpoint uses… | |
| Aplazada | Alta (8.2) | 0.58% | — | Wallosapp WallosAI | 31/8/2026 | 8/9/2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/import.php has no authentication. The only guard is a user-table row count — if zero (fresh/unconfigured install), an unauthenticated attacker can replace the entire database. This issue has been patched in… | |
| Aplazada | Alta (7.5) | 0.22% | — | Wallosapp WallosAI | 31/8/2026 | 8/9/2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, login.php generates an OIDC state nonce stored in $_SESSION['oidc_state'], but checksession.php dispatches the OIDC callback without comparing the incoming state against the session value. An attacker can trick a victim into… | |
| Aplazada | Alta (7.5) | 0.46% | — | Wallosapp WallosAI | 31/8/2026 | 8/9/2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/migrate.php executes database schema migrations when called over HTTP with zero authentication. Any unauthenticated attacker can trigger pending migration files against the live SQLite database. This issue has… | |
| Aplazada | Media (4.3) | 0.26% | — | Wallosapp WallosAI | 31/8/2026 | 8/9/2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, endpoints/currency/update_exchange.php loads the first Fixer/API Layer credential globally instead of loading the credential for the authenticated user. As a result, a normal authenticated user without their own provider key… | |
| Aplazada | Media (4.3) | 0.29% | — | Wallosapp WallosAI | 31/8/2026 | 8/9/2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, an authenticated user can edit their own inactive subscription and set replacement_subscription_id to a subscription ID belonging to another user. The write is accepted, and later the stats logic dereferences that foreign… | |
| Pendiente de análisis | Alta (7.5) | 0.44% | — | Gssapi With MIC ConfigAI | 28/8/2026 | 3/9/2026 | The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and… | |
| Pendiente de análisis | Alta (7.5) | 0.51% | — | SAP S/4hanaAI | 25/8/2026 | 26/8/2026 | SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnerability. An unauthenticated attacker could supply specially crafted input that triggers excessive processing within the affected functionality. Successful exploitation could exhaust system… | |
| Pendiente de análisis | Crítica (10) | 0.85% | 💥 PoC | SAP Commerce CloudAI | 11/8/2026 | 17/8/2026 | SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on… | |
| Pendiente de análisis | Media (6.3) | 0.35% | — | SAP Netweaver Application Server AbapAI | 11/8/2026 | 26/8/2026 | Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated victim accesses this link, the injected input is processed and reflected within the DOM on the client side during… | |
| Analizada | Media (5.3) | 0.36% | — | SAP Approuter | 11/8/2026 | 8/9/2026 | SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker could send a specially crafted request to obtain limited unauthorized access to information. This results in a low impact on confidentiality. There is no impact on… | |
| Analizada | Media (5.9) | 0.44% | — | SAP Approuter | 11/8/2026 | 8/9/2026 | SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the complexity of the required conditions, an attacker with low privileges could send specially crafted requests to bypass authorization checks and reach protected resources beyond their… | |
| Analizada | Media (5.9) | 0.20% | — | SAP Approuter | 11/8/2026 | 8/9/2026 | SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that bypasses the integrity check and loads another user's session context. Successful exploitation requires… | |
| Analizada | Media (4.3) | 0.17% | — | SAP Approuter | 11/8/2026 | 8/9/2026 | SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthenticated attacker could craft a malicious link and trick a victim into following it. Successful exploitation could allow the attacker to bind the victim's session to an attacker-controlled identity,… | |
| Analizada | Baja (3.7) | 0.35% | — | SAP Approuter | 11/8/2026 | 8/9/2026 | SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this under a non-default configuration. Successful exploitation is highly complex, as it depends on conditions outside the attacker's control. This could result in a low impact on availability. There is… | |
| Pendiente de análisis | Media (4.3) | 0.30% | — | SAP Businessobjects Business Intelligence PlatformAI | 11/8/2026 | 26/8/2026 | SAP BusinessObjects Business Intelligence Platform (Admin Tools) does not perform sufficient authorization check on certain administrative functionality. An attacker authenticated as a non-administrative user could bypass this restriction to gain limited information about affected functionality. This results in a low… | |
| Pendiente de análisis | Media (6.1) | 0.38% | — | Sapui5AI | 11/8/2026 | 26/8/2026 | SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted application changes. When another user subsequently opens the adapted application, the injected script executes in the victim's browser session. Successful exploitation could allow the attacker to access… | |
| Pendiente de análisis | Media (6.3) | 0.27% | — | SAP Social IntelligenceAI | 11/8/2026 | 26/8/2026 | Due to an SQL Injection vulnerability in SAP Social intelligence, an authenticated attacker could directly inject an SQL DDL (Data Definition Language) string into the underlying database without further authorization. Successful exploitation could allow the attacker to make malicious changes to the database… | |
| Pendiente de análisis | Media (4.3) | 0.28% | — | SAP S/4hanaAI | 11/8/2026 | 26/8/2026 | Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated users, allowing them to use rules that have not been shared with them, resulting in privilege escalation.This vulnerability has a low impact on confidentiality, with no impact on integrity and… | |
| Pendiente de análisis | Alta (7.9) | 0.20% | — | SAP Businessobjects Business Intelligence PlatformAI | 11/8/2026 | 26/8/2026 | SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects and decrypt the stored credentials. Successful exploitation could allow… | |
| Analizada | Media (4.3) | 0.38% | — | SAP Approuter | 11/8/2026 | 8/9/2026 | SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could send high volumes of data without consuming responses, causing unbounded memory growth. This results in a low impact on availability. There is no impact on confidentiality and integrity. | |
| Analizada | Media (6.4) | 0.18% | — | SAP Approuter | 11/8/2026 | 8/9/2026 | SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from the same trusted authority with matching subject values, could bypass the identity check. This complexity makes the attack difficult to execute. Successful exploitation… |