Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
2261 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.3) | 0.24% | — | SAP Netweaver Application Server FOR AbapAISAP Abap PlatformAI | 28/7/2026 | 28/7/2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their… | |
| Aplazada | Media (4.3) | 0.36% | — | Bizimhesap Information Systems Industry AND Trade INC Online Pre-accounting SoftwareAI | 23/7/2026 | 23/7/2026 | Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade Inc. Online Pre-Accounting Software allows Excessive Allocation. This issue affects Online Pre-Accounting Software: through 17072026. | |
| Analizada | Alta (7.1) | 0.21% | — | Verygoodplugins Whatsapp MCP Server | 20/7/2026 | 18/8/2026 | WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages. Prior to version 0.2.1, the `whatsapp-bridge` HTTP API listens on `127.0.0.1:8080` without authentication and without Host header validation, and the `/api/send` endpoint accepts an absolute… | |
| Aplazada | Crítica (9.3) | 0.52% | — | SAP Cloud Application Programming ModelAICap-js Db-serviceAISqliteAISupabase PostgresAI | 15/7/2026 | 15/7/2026 | The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that tool. On April 29, 2026, compromised versions of `@cap-js/sqlite@2.2.2`, `@cap-js/postgres@2.2.2`, and `@cap-js/db-service@2.10.1` were… | |
| Pendiente de análisis | Alta (7.6) | 0.56% | — | SAP Change AND Transport System Attach ToolAI | 14/7/2026 | 14/7/2026 | SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application�s library, can trigger insecure deserialization and lead to remote code execution (RCE) on the system. Successful exploitation requires a victim… | |
| Pendiente de análisis | Media (4.3) | 0.28% | — | SAP S/4hanaAI | 14/7/2026 | 14/7/2026 | SAP S/4HANA Draft operation does not perform necessary authorization checks for an authenticated user, a restricted user could access information within the entity resulting in escalation of privileges. This results in low impact on confidentiality, with no impact on integrity and availability of the application. | |
| Pendiente de análisis | Media (4.3) | 0.28% | — | SAP Create Single PaymentAI | 14/7/2026 | 14/7/2026 | SAP Create Single Payment does not perform necessary authorization checks for an authenticated user, a restricted user could access specific entity set keys resulting in disclosure of information. This has low impact on confidentiality, with no impact on integrity and availability of the application. | |
| Pendiente de análisis | Media (5.5) | 0.31% | — | SAP S/4hanaAI | 14/7/2026 | 14/7/2026 | SAP S/4HANA application Project Management (PPM-PRO) allows an attacker with high privileges to execute crafted database queries, exposing the backend database. This results in low impact on confidentiality, with no impact on integrity and availability of the application. | |
| Pendiente de análisis | Media (4.1) | 0.26% | — | SAP CRM Webclient UIAI | 14/7/2026 | 14/7/2026 | SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of the application due to the absence of a Content Security Policy (CSP) configuration for certain restrictive directives. This vulnerability has a low impact on the integrity of the application. Confidentiality and… | |
| Pendiente de análisis | Media (6.1) | 0.29% | — | SAP UI5AI | 14/7/2026 | 14/7/2026 | setThemeRoot() failed to enforce the sap-allowed-theme-origins allowlist. An attacker-controlled absolute cross-origin URL could be stored and used directly to construct a <link rel=stylesheet> element, even when no <meta name=sap-allowed-theme-origins> tag was present in the document. The same bypass was reachable… | |
| Pendiente de análisis | Crítica (9.1) | 0.50% | — | SAP Commerce CloudAI | 14/7/2026 | 15/7/2026 | SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain… | |
| Pendiente de análisis | Media (4.7) | 0.23% | — | SAP Netweaver Application Server AbapAI | 14/7/2026 | 14/7/2026 | Due to a Cross-Site Scripting (XSS) vulnerability, applications based on Business Server Pages framework in SAP NetWeaver Application Server ABAP reflects unsanitized input into the HTTP response which allows an attacker to inject and execute arbitrary JavaScript code under certain conditions. Successful exploitation… | |
| Pendiente de análisis | Media (6.1) | 0.29% | — | SAP Netweaver Enterprise PortalAI | 14/7/2026 | 14/7/2026 | SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the server response and executed in a user's browser when the crafted URL is visited, leading to theft of session information, manipulation of portal content, or user… | |
| Pendiente de análisis | Baja (3.7) | 0.35% | — | SAP Hana DatabaseAI | 14/7/2026 | 14/7/2026 | SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produce distinguishable responses, enabling enumeration of valid user accounts and email addresses. Successful exploitation could allow the attacker to enumerate valid user accounts, resulting in low… | |
| Pendiente de análisis | Alta (8.2) | 0.36% | — | SAP Netweaver Application Server JavaAI | 14/7/2026 | 14/7/2026 | SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted URLs. When a victim accesses such a URL, the script executes in the user's browser, allowing the attacker to access sensitive session information and modify non-sensitive data displayed in the… | |
| Pendiente de análisis | Crítica (9.9) | 0.56% | — | SAP Netweaver Application Server AbapAI | 14/7/2026 | 29/7/2026 | SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability. This has high impact on confidentiality, integrity, and availability of the… | |
| Analizada | Alta (8.1) | 0.47% | — | SAP Approuter | 14/7/2026 | 8/9/2026 | SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to… | |
| Analizada | Crítica (9.1) | 0.68% | — | SAP Approuter | 14/7/2026 | 8/9/2026 | Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on… | |
| Pendiente de análisis | Alta (8.4) | 0.21% | — | SaprouterAIMicrosoft WindowsAI | 14/7/2026 | 20/7/2026 | SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code on the system. This could enable the attacker to hijack the DLL loading process and achieve arbitrary code execution. This has high impact on… | |
| Aplazada | Alta (8.5) | 0.17% | — | Brother SapsprintAI | 19/6/2026 | 23/6/2026 | Brother SAPSprint 7.60 contains an unquoted service path vulnerability in the SAPSprint service binary that allows local attackers to escalate privileges. Attackers can place a malicious executable in the Program Files directory path to be executed with LocalSystem privileges when the service starts automatically. | |
| Pendiente de análisis | Media (4.7) | 0.24% | — | SAP Wily Introscope Enterprise ManagerAI | 9/6/2026 | 23/7/2026 | SAP Wily Introscope Enterprise Manager allows an unauthenticated attacker to craft a specially crafted URL. Under certain conditions, when accessed by a victim, the injected script could execute in the user�s browser within the context of the application. This issue has a low impact on the confidentiality and… | |
| Pendiente de análisis | Media (4.3) | 0.15% | — | SAP Business Objects Business Intelligence PlatformAI | 9/6/2026 | 23/7/2026 | SAP Business Objects Business Intelligence Platform does not sufficiently validate email sending parameters supplied by authenticated users, resulting in an email spoofing vulnerability.This vulnerability has a low impact on integrity and does not affect the confidentiality and availability of the application. | |
| Pendiente de análisis | Media (6.6) | 0.35% | — | SAP Operational Data Provisioning Data Replication APIAI | 9/6/2026 | 23/7/2026 | The Remote Function Call (RFC) modules of the Operational Data Provisioning Data Replication API (ODP-RFC) are missing caller identification of permitted SAP-internal applications and are being used by customer or third-party applications in ways that are not aligned with its intended usage. Which could lead to… | |
| Pendiente de análisis | Alta (7.1) | 0.35% | — | SAP Application Server AbapAI | 9/6/2026 | 23/7/2026 | Application server ABAP does not perform necessary authorization checks for an authenticated user allowing an attacker to execute a report generation command which could overwrite information belonging to another user, resulting in escalation of privileges. This has high impact on integrity with low impact on… | |
| Pendiente de análisis | Media (4.3) | 0.26% | — | SAP Master Data GovernanceAI | 9/6/2026 | 23/7/2026 | SAP MDG (Review Match Groups Application) does not perform the necessary authorization checks for authenticated users. This could allow a low-privileged user to perform actions that would otherwise be restricted, resulting in escalation of privileges. This has a low impact on integrity, while confidentiality and… |