Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

2261 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.5)0.39%—SAP Businessobjects Business Intelligence PlatformAISAP WEB IntelligenceAI11/8/202626/8/2026
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file containing malicious external references. When the file is processed as a data source, the affected component resolves these references and exposes the contents of…
Pendiente de análisisMedia (5.3)0.36%—SAP Abap PlatformAI11/8/202626/8/2026
SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This could disclose limited, non-sensitive data from previously used memory, leading to a low on confidentiality, with no impact on integrity and availability of the application.
Pendiente de análisisBaja (3.8)0.29%—SAP Advanced Planning AND OptimizationAI11/8/202626/8/2026
SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of the application to perform authorization check to access certain functionalities in the application. An attacker with high privileges could leverage this hardcoded credential to bypass authorization…
Pendiente de análisisMedia (4.3)0.28%—SAP Manufacturing Integration AND IntelligenceAI11/8/202626/8/2026
SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain application function, allowing a low-privileged authenticated attacker to access information that should be restricted to privileged users. Successful exploitation could allow the attacker to access the users…
Pendiente de análisisAlta (8.8)0.44%—SAP Abap Development ToolsAISAP Netweaver AS AbapAI11/8/202626/8/2026
SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could allow the attacker to read sensitive data, modify application data, and…
Pendiente de análisisMedia (4.2)0.25%—SAP NetweaverAISAP Abap PlatformAI11/8/202626/8/2026
SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard) allows a low-privileged user to modify configuration tables that control access to data objects during specific operations. These unauthorized modifications could result in processing delays and operational…
AnalizadaBaja (3.7)0.35%—SAP Approuter11/8/20268/9/2026
SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send specially crafted requests to spoof the tenant context under conditions not fully within their control. Successful exploitation could allow limited access to another tenant's information, resulting…
AnalizadaMedia (5.9)0.43%—SAP Approuter11/8/20268/9/2026
SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input that causes the component to crash and restart. Successful exploitation requires specific runtime conditions to be met, making the attack complex to execute. This…
AnalizadaMedia (5.9)0.28%—SAP Approuter11/8/20268/9/2026
WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit this to access restricted functionality. Successful exploitation could allow the attacker to read sensitive information and perform limited modifications, resulting in a…
Pendiente de análisisMedia (5.5)0.69%—SAP Netweaver Application Server AbapAISAP Abap PlatformAI11/8/202626/8/2026
SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing security controls on an internal code path leading to operating system command execution. Successful exploitation could allow the attacker to execute OS-level commands that write to the operating system or…
Pendiente de análisisMedia (6.3)0.29%—SAP Netweaver Application Server JavaAIAdobe Document ServiceAI11/8/202626/8/2026
SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer libraries that contain known vulnerabilities addressed in later versions. A low-privileged authenticated attacker could potentially leverage these weaknesses against the affected component, though…
AnalizadaAlta (7)0.31%—SAP Approuter11/8/20268/9/2026
SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlled destination. The attack complexity is high due to non-default preconditions…
Pendiente de análisisAlta (7.3)0.38%—SAP Manufacturing Integration AND IntelligenceAI11/8/202626/8/2026
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access scheduling-related application functions without proper authorization validation. Successful exploitation could allow the attacker to retrieve, create, modify, or delete…
Pendiente de análisisAlta (7.3)0.32%—SAP Manufacturing Integration AND IntelligenceAI11/8/202626/8/2026
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parameter values. If processed by the application, these requests enable access to backend operations. Successful exploitation…
Pendiente de análisisAlta (7.6)0.40%—SAP Manufacturing Integration AND IntelligenceAI11/8/202626/8/2026
SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and depends on conditions outside the…
Pendiente de análisisBaja (3.7)0.19%—SAP Data Services Management ConsoleAI11/8/202626/8/2026
SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks certain restrictive directives, which could enable an authenticated malicious user to leverage this weakness in combination with another vulnerability to inject and execute malicious scripts within…
Pendiente de análisisCrítica (9.1)0.77%—SAP Manufacturing Integration AND IntelligenceAI11/8/202626/8/2026
SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating…
Pendiente de análisisMedia (5.3)0.47%—SapsprintAI11/8/202626/8/2026
SAP SAPSPrint Service has memory corruption vulnerabilities in the handling of certain commands. An unauthenticated attacker could send specially crafted requests that trigger a buffer overflow in the affected component. This causes a temporary service interruption and automatic restart, resulting in low impact on…
Pendiente de análisisCrítica (9.8)0.64%—SAP Netweaver Application Server AbapAI11/8/202626/8/2026
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the system, leading to a high impact on the confidentiality, integrity, and…
AplazadaCrítica (9.8)0.66%—SAP GUIAI5/8/202626/8/2026
IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding with no sanitization of the decoded value before it is…
AplazadaAlta (7.3)0.20%—Sourcecodester Casap Automated Enrollment SystemAI29/7/20261/10/2026
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter status.
AplazadaAlta (7.3)0.20%—Sourcecodester Casap Automated Enrollment SystemAI29/7/20261/10/2026
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters fname and student_class.
AplazadaAlta (7.3)0.20%—Sourcecodester Casap Automated Enrollment SystemAI29/7/20261/10/2026
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the parameter new_password.
AplazadaCrítica (9.8)0.32%—Sourcecodester Casap Automated Enrollment SystemAI29/7/20261/10/2026
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_class.
AplazadaCrítica (9.8)0.32%—Sourcecodester Casap Automated Enrollment SystemAI29/7/20261/10/2026
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name.