Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
2261 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.9) | 0.32% | — | SAP Netweaver Application Server AbapAISAP Abap PlatformAI | 9/6/2026 | 23/7/2026 | SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tampered identity information leading to unauthorized access to sensitive user data… | |
| Pendiente de análisis | Media (6.1) | 0.34% | — | SAP Netweaver JavaAI | 9/6/2026 | 23/7/2026 | Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver JAVA (JDBC Test Servlet), an unauthenticated attacker could craft a URL that embeds a malicious script. If a victim clicks this link, the injected input is processed during web page generation, resulting in the execution of malicious content… | |
| Pendiente de análisis | Media (6.5) | 0.38% | — | SAP S/4hanaAI | 9/6/2026 | 23/7/2026 | SAP S/4HANA(On-Premise) contains SQL injection vulnerability in a remote-enabled function module component that could be exploited by an authenticated attacker to potentially execute unauthorized database queries.This flaw exposes sensitive information to which they should not otherwise have access to. The… | |
| Pendiente de análisis | Baja (3.7) | 0.30% | — | SAP Business ObjectsAI | 9/6/2026 | 23/7/2026 | Under certain conditions, when an unauthorized attacker accesses a specific endpoint, SAP Business Objects application leaks sensitive information .This has a low impact on the confidentiality of the data. There is no impact on integrity and availability of the application. | |
| Pendiente de análisis | Crítica (9) | 0.63% | — | SAP Netweaver Application Server JavaAI | 9/6/2026 | 23/7/2026 | SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the included file could allow the attacker to view or modify sensitive… | |
| Pendiente de análisis | Crítica (9.8) | 0.62% | — | SAP NetweaverAISAP Abap PlatformAISAP KernelAI | 9/6/2026 | 23/7/2026 | Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated attacker can send a crafted RFC request that exploits logical errors in memory management, leading to memory corruption. This could lead to a high impact on the… | |
| Pendiente de análisis | Media (4.2) | 0.17% | — | SAP Fiori LaunchpadAI | 9/6/2026 | 23/7/2026 | SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain, this when opened by the user could compromise accounts by stealing user credentials. Successful exploitation requires adversaries to possess advanced knowledge of the system causing low impact on… | |
| Aplazada | Baja (2) | 0.27% | — | Lharries Whatsapp-mcpAI | 1/6/2026 | 22/7/2026 | A vulnerability was determined in lharries whatsapp-mcp 0.0.1. Affected by this vulnerability is the function SendMessageRequest of the file whatsapp-bridge/main.go of the component Send API Endpoint. This manipulation of the argument mediaPath causes path traversal. The exploit has been publicly disclosed and may be… | |
| Pendiente de análisis | Media (4.3) | 0.32% | — | SAP GatewayAI | 26/5/2026 | 24/7/2026 | The SAP Gateway allows attackers to inject content into error messages, potentially leading to disclosure of request artefacts (e.g., regex patterns) and revealing underlying URI parsing logic. Leading to low impact on confidentiality. Integrity and availability are unaffected. | |
| Modificada | Alta (7.5) | 1.1% | — | GnutlsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux+10 | 18/5/2026 | 2/10/2026 | A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable… | |
| Analizada | Media (4.3) | 0.29% | — | SAP Netweaver Application Server Abap | 14/5/2026 | 17/6/2026 | Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inject custom Cascading Style Sheets (CSS) data into a web page served by the application. When a user accesses or clicks the affected page, the injected CSS is executed. As a result, the issue has a… | |
| Pendiente de análisis | Media (6.1) | 0.29% | — | SAP TAF ApplauncherAI | 12/5/2026 | 17/6/2026 | SAP TAF_APPLAUNCHER within Business Server Pages allows an unauthenticated attacker to craft malicious links that, when clicked by a victim, redirects them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on confidentiality and… | |
| Pendiente de análisis | Media (4.3) | 0.37% | — | SAP Financial ConsolidationAI | 12/5/2026 | 17/6/2026 | SAP Financial Consolidation allows an authenticated attacker to disconnect other users by terminating their sessions temporarily preventing access. However, the application itself cannot be compromised resulting in a low impact on availability. There is no impact on confidentiality and integrity of the data | |
| Analizada | Media (6.5) | 1.9% | — | SAP Netweaver Application Server Abap | 12/5/2026 | 17/6/2026 | An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an authenticated attacker with administrative access to execute specially crafted shell commands on the server, bypassing the logging mechanism. This allows the execution of unintended OS… | |
| Pendiente de análisis | Media (4.3) | 0.26% | — | SAP Incentive AND Commission ManagementAI | 12/5/2026 | 17/6/2026 | Due to insufficient authorization checks in the SAP Incentive and Commission Management application, authenticated users could invoke a remote-enabled function module to perform table update operations. This vulnerability has a low impact on integrity with no impact on confidentiality and availability of the… | |
| Pendiente de análisis | Media (6.3) | 0.27% | — | SAP S/4hanaAI | 12/5/2026 | 17/6/2026 | Due to missing authorization check in SAP S/4HANA Condition Maintenance, an authenticated attacker could gain unauthorized access to view and modify condition table records, resulting in low impact on the confidentiality and integrity of the data. Additionally, this vulnerability may prevent the legitimate user from… | |
| Pendiente de análisis | Media (5.4) | 0.24% | — | SAP Strategic Enterprise ManagementAI | 12/5/2026 | 17/6/2026 | Due to missing authorization check in SAP Strategic Enterprise Management (Scorecard Wizard in Business Server Pages), an authenticated attacker could access information that they are otherwise unauthorized to view. This vulnerability also enables the attacker to change the default settings and modify value fields,… | |
| Pendiente de análisis | Baja (3.4) | 0.18% | — | SAP Hdi-deployAI | 12/5/2026 | 17/6/2026 | SQL injection vulnerability exists in @sap/hdi-deploy package, where SQL queries are dynamically constructed using user input without proper parameterization or prepared statements. Successful exploitation could allow the high privileged users to alter the SELECT statements impacting confidentiality and availability… | |
| Pendiente de análisis | Media (4.3) | 0.34% | — | SAP Application Server AbapAISAP NetweaverAISAP Abap PlatformAI | 12/5/2026 | 17/6/2026 | Due to a Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform, an authenticated attacker could send specially crafted inputs to the application. If processed by the application, this input could be delivered to users subscribed to the channel and result in execution.… | |
| Pendiente de análisis | Crítica (9.6) | 0.62% | — | SAP Commerce CloudAIVmware SecurityAI | 12/5/2026 | 17/6/2026 | Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious input injection, resulting in arbitrary server-side code execution, leading to high impact on Confidentiality, Integrity, and Availability of the application. | |
| Pendiente de análisis | Crítica (9.6) | 0.43% | — | SAP S/4hanaAI | 12/5/2026 | 17/6/2026 | SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to inject malicious SQL statements through user-controlled input. The application directly concatenates this malicious user input into SQL queries, which are then passed to the underlying database… | |
| Pendiente de análisis | Alta (8.2) | 0.24% | — | SAP Forecasting AND ReplenishmentAI | 12/5/2026 | 17/6/2026 | Due to an OS Command Execution vulnerability in SAP Forecasting & Replenishment, an authenticated attacker with administrative authorizations could abuse a non-remote-enabled function to execute arbitrary operating system commands. Successful exploitation could allow the attacker to read or modify any system data or… | |
| Pendiente de análisis | Media (4.7) | 0.32% | — | Sapui5AI | 12/5/2026 | 17/6/2026 | SAPUI5 (Search UI) allows an unauthenticated attacker to manipulate specific URL parameters on the Search UI to include malicious content. Successful exploitation may mislead victim users into clicking and accessing attacker-controlled pages rendered by the application. This vulnerability has a low impact on… | |
| Analizada | Media (6.1) | 0.30% | — | SAP Netweaver Application Server Abap | 12/5/2026 | 17/6/2026 | Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages), an unauthenticated attacker could craft a URL that exploits an unprotected URL parameter to embed a malicious script. If a victim clicks the link, the injected input is… | |
| Pendiente de análisis | Media (5.4) | 0.12% | — | SAP Businessobjects Business Intelligence PlatformAI | 12/5/2026 | 17/6/2026 | Due to insufficient CSRF protection in SAP BusinessObjects Business Intelligence Platform ,an authenticated user could be tricked by an attacker to send unintended requests to the web server. This has low impact on integrity and availability of the application. There is no impact on confidentiality of the data. |