Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

2261 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (4.3)0.24%—SAP Netweaver Application Server FOR AbapAISAP Abap PlatformAI28/7/202628/7/2026
SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their…
AplazadaMedia (4.3)0.36%—Bizimhesap Information Systems Industry AND Trade INC Online Pre-accounting SoftwareAI23/7/202623/7/2026
Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade Inc. Online Pre-Accounting Software allows Excessive Allocation. This issue affects Online Pre-Accounting Software: through 17072026.
AnalizadaAlta (7.1)0.21%—Verygoodplugins Whatsapp MCP Server20/7/202618/8/2026
WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages. Prior to version 0.2.1, the `whatsapp-bridge` HTTP API listens on `127.0.0.1:8080` without authentication and without Host header validation, and the `/api/send` endpoint accepts an absolute…
AplazadaCrítica (9.3)0.52%—SAP Cloud Application Programming ModelAICap-js Db-serviceAISqliteAISupabase PostgresAI15/7/202615/7/2026
The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that tool. On April 29, 2026, compromised versions of `@cap-js/sqlite@2.2.2`, `@cap-js/postgres@2.2.2`, and `@cap-js/db-service@2.10.1` were…
Pendiente de análisisAlta (7.6)0.56%—SAP Change AND Transport System Attach ToolAI14/7/202614/7/2026
SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application�s library, can trigger insecure deserialization and lead to remote code execution (RCE) on the system. Successful exploitation requires a victim…
Pendiente de análisisMedia (4.3)0.28%—SAP S/4hanaAI14/7/202614/7/2026
SAP S/4HANA Draft operation does not perform necessary authorization checks for an authenticated user, a restricted user could access information within the entity resulting in escalation of privileges. This results in low impact on confidentiality, with no impact on integrity and availability of the application.
Pendiente de análisisMedia (4.3)0.28%—SAP Create Single PaymentAI14/7/202614/7/2026
SAP Create Single Payment does not perform necessary authorization checks for an authenticated user, a restricted user could access specific entity set keys resulting in disclosure of information. This has low impact on confidentiality, with no impact on integrity and availability of the application.
Pendiente de análisisMedia (5.5)0.31%—SAP S/4hanaAI14/7/202614/7/2026
SAP S/4HANA application Project Management (PPM-PRO) allows an attacker with high privileges to execute crafted database queries, exposing the backend database. This results in low impact on confidentiality, with no impact on integrity and availability of the application.
Pendiente de análisisMedia (4.1)0.26%—SAP CRM Webclient UIAI14/7/202614/7/2026
SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of the application due to the absence of a Content Security Policy (CSP) configuration for certain restrictive directives. This vulnerability has a low impact on the integrity of the application. Confidentiality and…
Pendiente de análisisMedia (6.1)0.29%—SAP UI5AI14/7/202614/7/2026
setThemeRoot() failed to enforce the sap-allowed-theme-origins allowlist. An attacker-controlled absolute cross-origin URL could be stored and used directly to construct a <link rel=stylesheet> element, even when no <meta name=sap-allowed-theme-origins> tag was present in the document. The same bypass was reachable…
Pendiente de análisisCrítica (9.1)0.50%—SAP Commerce CloudAI14/7/202615/7/2026
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain…
Pendiente de análisisMedia (4.7)0.23%—SAP Netweaver Application Server AbapAI14/7/202614/7/2026
Due to a Cross-Site Scripting (XSS) vulnerability, applications based on Business Server Pages framework in SAP NetWeaver Application Server ABAP reflects unsanitized input into the HTTP response which allows an attacker to inject and execute arbitrary JavaScript code under certain conditions. Successful exploitation…
Pendiente de análisisMedia (6.1)0.29%—SAP Netweaver Enterprise PortalAI14/7/202614/7/2026
SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the server response and executed in a user's browser when the crafted URL is visited, leading to theft of session information, manipulation of portal content, or user…
Pendiente de análisisBaja (3.7)0.35%—SAP Hana DatabaseAI14/7/202614/7/2026
SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produce distinguishable responses, enabling enumeration of valid user accounts and email addresses. Successful exploitation could allow the attacker to enumerate valid user accounts, resulting in low…
Pendiente de análisisAlta (8.2)0.36%—SAP Netweaver Application Server JavaAI14/7/202614/7/2026
SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted URLs. When a victim accesses such a URL, the script executes in the user's browser, allowing the attacker to access sensitive session information and modify non-sensitive data displayed in the…
Pendiente de análisisCrítica (9.9)0.56%—SAP Netweaver Application Server AbapAI14/7/202629/7/2026
SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability. This has high impact on confidentiality, integrity, and availability of the…
AnalizadaAlta (8.1)0.47%—SAP Approuter14/7/20268/9/2026
SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to…
AnalizadaCrítica (9.1)0.68%—SAP Approuter14/7/20268/9/2026
Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on…
Pendiente de análisisAlta (8.4)0.21%—SaprouterAIMicrosoft WindowsAI14/7/202620/7/2026
SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code on the system. This could enable the attacker to hijack the DLL loading process and achieve arbitrary code execution. This has high impact on…
AplazadaAlta (8.5)0.17%—Brother SapsprintAI19/6/202623/6/2026
Brother SAPSprint 7.60 contains an unquoted service path vulnerability in the SAPSprint service binary that allows local attackers to escalate privileges. Attackers can place a malicious executable in the Program Files directory path to be executed with LocalSystem privileges when the service starts automatically.
Pendiente de análisisMedia (4.7)0.24%—SAP Wily Introscope Enterprise ManagerAI9/6/202623/7/2026
SAP Wily Introscope Enterprise Manager allows an unauthenticated attacker to craft a specially crafted URL. Under certain conditions, when accessed by a victim, the injected script could execute in the user�s browser within the context of the application. This issue has a low impact on the confidentiality and…
Pendiente de análisisMedia (4.3)0.15%—SAP Business Objects Business Intelligence PlatformAI9/6/202623/7/2026
SAP Business Objects Business Intelligence Platform does not sufficiently validate email sending parameters supplied by authenticated users, resulting in an email spoofing vulnerability.This vulnerability has a low impact on integrity and does not affect the confidentiality and availability of the application.
Pendiente de análisisMedia (6.6)0.35%—SAP Operational Data Provisioning Data Replication APIAI9/6/202623/7/2026
The Remote Function Call (RFC) modules of the Operational Data Provisioning Data Replication API (ODP-RFC) are missing caller identification of permitted SAP-internal applications and are being used by customer or third-party applications in ways that are not aligned with its intended usage. Which could lead to…
Pendiente de análisisAlta (7.1)0.35%—SAP Application Server AbapAI9/6/202623/7/2026
Application server ABAP does not perform necessary authorization checks for an authenticated user allowing an attacker to execute a report generation command which could overwrite information belonging to another user, resulting in escalation of privileges. This has high impact on integrity with low impact on…
Pendiente de análisisMedia (4.3)0.26%—SAP Master Data GovernanceAI9/6/202623/7/2026
SAP MDG (Review Match Groups Application) does not perform the necessary authorization checks for authenticated users. This could allow a low-privileged user to perform actions that would otherwise be restricted, resulting in escalation of privileges. This has a low impact on integrity, while confidentiality and…