Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

491 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.2)0.34%—SAP NetweaverAI13/5/202517/6/2026
SAP NetWeaver is vulnerable to an Information Disclosure vulnerability caused by the injection of malicious instructions into user configuration settings. An attacker with administrative privileges can craft these instructions so that when accessed by the victim, sensitive information such as user credentials is…
AnalizadaCrítica (9.8)99%⚠ Explotación activa💥 ExploitSAP Netweaver24/4/20254/8/2026
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted…
AplazadaMedia (4.3)0.35%—SAP NetweaverAI8/4/202517/6/2026
SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would normally require additional validation. Once logged into the ABAP system, the attacker can run a specific transaction that exposes sensitive system code without proper authorization. This…
AplazadaMedia (4.1)0.26%—SAP NetweaverAISAP Abap PlatformAI8/4/202517/6/2026
Due to incorrect memory address handling in ABAP SQL of SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker with high privileges could execute certain forms of SQL queries leading to manipulation of content in the output variable. This vulnerability has a low impact on the…
AplazadaMedia (4.3)0.27%—SAP Netweaver Application Server AbapAI8/4/202517/6/2026
A Missing Authorization Check vulnerability exists in the Virus Scanner Interface of SAP NetWeaver Application Server ABAP. Because of this, an attacker authenticated as a non-administrative user can initiate a transaction, allowing them to access but not modify non-sensitive data without further authorization and…
AplazadaMedia (4.7)0.24%—SAP Netweaver Application Server AbapAI8/4/202517/6/2026
SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an attacker, without requiring any privileges, to inject malicious JavaScript into a website. When a user visits the compromised page, the injected script…
AplazadaAlta (8.5)0.50%—SAP Netweaver Application Server AbapAI8/4/202517/6/2026
In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, which can be used to expose credentials for a remote service. These credentials can then be further exploited to completely compromise the remote…
AplazadaMedia (5.4)0.22%—SAP Netweaver Application Server JavaAI11/3/202517/6/2026
User management functionality in SAP NetWeaver Application Server Java is vulnerable to Stored Cross-Site Scripting (XSS). This could enable an attacker to inject malicious payload that gets stored and executed when a user accesses the functionality, hence leading to information disclosure or unauthorized data…
AplazadaAlta (8.8)0.42%—SAP NetweaverAI11/3/202517/6/2026
Due to missing authorization check, SAP NetWeaver (ABAP Class Builder) allows an attacker to gain higher access levels than they should have, resulting in escalation of privileges. On successful exploitation, this could result in disclosure of highly sensitive information. It could also have a high impact on the…
AplazadaMedia (6.1)0.24%—SAP Netweaver Application Server AbapAI11/3/202517/6/2026
SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to DOM-basedCross-Site Scripting (XSS) vulnerability. This allows an attacker with no privileges, to craft a malicious web message that exploits WEBGUI functionality. On successful exploitation, the malicious JavaScript…
AplazadaMedia (6.1)0.25%—SAP Netweaver Application Server AbapAI11/3/202517/6/2026
SAP NetWeaver Application Server ABAP allows malicious scripts to be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application, but it can have some minor impact on its confidentiality and integrity.
AplazadaMedia (5.3)0.32%—SAP Netweaver Enterprise PortalAI11/3/202517/6/2026
SAP NetWeaver Enterprise Portal OBN does not perform proper authentication check for a particular configuration setting. As result, a non-authenticated user can set it to an undesired value causing low impact on integrity. There is no impact on confidentiality or availability of the application.
AplazadaMedia (4.3)0.26%—SAP Netweaver Application Server JavaAI11/2/202517/6/2026
SAP NetWeaver Application Server Java allows an attacker to access an endpoint that can disclose information about deployed server components, including their XML definitions. This information should ideally be restricted to customer administrators, even though they may not need it. These XML files are not entirely…
AplazadaMedia (5.4)0.27%💥 PoCSAP Netweaver Application Server JavaAI11/2/202517/6/2026
SAP NetWeaver Application Server Java does not sufficiently handle user input, resulting in a stored cross-site scripting vulnerability. The application allows attackers with basic user privileges to store a Javascript payload on the server, which could be later executed in the victim's web browser. With this the…
AplazadaCrítica (9.9)0.70%—SAP Netweaver Application Server FOR AbapAISAP Abap PlatformAI14/1/202517/6/2026
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate access to the system by exploiting improper authentication checks, resulting in privilege escalation. On successful exploitation, this can result in potential security concerns. This results in a high…
AplazadaMedia (4.3)0.27%—SAP Netweaver Application Server AbapAI14/1/202517/6/2026
An obsolete functionality in SAP NetWeaver Application Server ABAP did not perform necessary authorization checks. Because of this, an authenticated attacker could obtain information that would otherwise be restricted. It has no impact on integrity or availability on the application.
AplazadaMedia (6.3)0.26%—SAP Netweaver Application Server JavaAI14/1/202517/6/2026
Due to a missing authorization check on service endpoints in the SAP NetWeaver Application Server Java, an attacker with standard user role can create JCo connection entries, which are used for remote function calls from or to the application server. This could lead to low impact on confidentiality, integrity, and…
AplazadaMedia (6)0.18%—SAP Netweaver Application Server AbapAISAP GUI FOR HtmlAI14/1/202517/6/2026
Applications based on SAP GUI for HTML in SAP NetWeaver Application Server ABAP store user input in the local browser storage to improve usability. An attacker with administrative privileges or access to the victim�s user directory on the Operating System level would be able to read this data. Depending on the user…
AplazadaMedia (4.8)0.24%—SAP Netweaver AS JavaAI14/1/202517/6/2026
SAP NetWeaver AS JAVA (User Admin Application) is vulnerable to stored cross site scripting vulnerability. An attacker posing as an admin can upload a photo with malicious JS content. When a victim visits the vulnerable component, the attacker can read and modify information within the scope of victim's web browser.
AplazadaAlta (8.5)0.60%—SAP Netweaver Application Server AbapAI10/12/202417/6/2026
In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, which can be used to expose credentials for a remote service. These credentials can then be further exploited to completely compromise the remote…
AplazadaAlta (7.2)0.27%—SAP Netweaver AdministratorAI10/12/202417/6/2026
SAP NetWeaver Administrator(System Overview) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in Server-Side Request Forgery (SSRF) which could have a low impact on integrity and…
AplazadaMedia (4.3)0.27%—SAP Netweaver Application Server FOR AbapAISAP Abap PlatformAI10/12/202417/6/2026
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to gain higher access levels than they should have by exploiting improper authorization checks, resulting in privilege escalation. While authorizations for import and export are distinguished, a single authorization is applied…
AplazadaMedia (4.3)0.38%—SAP Netweaver Application Server AbapAISAP WEB DispatcherAISAP GUI FOR HtmlAI12/11/202417/6/2026
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the server, which otherwise would be restricted.This attack is possible only if a Web Dispatcher or some sort of Proxy Server is in use and the file in question was previously opened or downloaded in an…
AplazadaMedia (5.3)0.31%—SAP Netweaver AS JavaAI12/11/202417/6/2026
SAP NetWeaver AS Java allows an unauthenticated attacker to brute force the login functionality in order to identify the legitimate user IDs. This has an impact on confidentiality but not on integrity or availability.
AplazadaMedia (4.7)0.13%—SAP Netweaver JavaAISAP Software Update ManagerAI12/11/202417/6/2026
In SAP NetWeaver Java (Software Update Manager 1.1), under certain conditions when a software upgrade encounters errors, credentials are written in plaintext to a log file. An attacker with local access to the server, authenticated as a non-administrative user, can acquire the credentials from the logs. This leads to…