Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
1234 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.18% | — | IBM Websphere Application Server | 12/8/2025 | 17/6/2026 | IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Alta (7.5) | 0.40% | — | IBM Websphere Application Server | 12/8/2025 | 17/6/2026 | IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to bypass security restrictions caused by a failure to honor JMS messaging configuration | |
| Aplazada | Alta (8.1) | 0.42% | — | SAP Netweaver Application Server AbapAI | 12/8/2025 | 17/6/2026 | SAP NetWeaver Application Server ABAP (BIC Document) allows an authenticated attacker to craft a request that, when submitted to a BIC Document application, could cause a memory corruption error. On successful exploitation, this results in the crash of the target component. Multiple submissions can make the target… | |
| Aplazada | Media (6.1) | 0.26% | — | SAP Netweaver Application Server AbapAISAP BIC DocumentAI | 12/8/2025 | 17/6/2026 | SAP NetWeaver Application Server ABAP (BIC Document) allows an unauthenticated attacker to craft a URL link which, when accessed on the BIC Document application, embeds a malicious script. When a victim clicks on this link, the script executes in the victim's browser, allowing the attacker to access and/or modify… | |
| Aplazada | Media (6.1) | 0.21% | — | SAP Netweaver Application Server AbapAI | 12/8/2025 | 17/6/2026 | SAP NetWeaver Application Server ABAP has HTML injection vulnerability. Due to this, an attacker could craft a URL with malicious script as payload and trick a victim with active user session into executing it. Upon successful exploit, this vulnerability could lead to limited access to data or its manipulation. There… | |
| Aplazada | Media (4.5) | 0.32% | — | SAP GUI FOR WindowsAISAP Application Server AbapAI | 12/8/2025 | 17/6/2026 | SAP GUI for Windows may allow the leak of NTML hashes when specific ABAP frontend services are called with UNC paths. For a successful attack, the attacker needs developer authorization in a specific Application Server ABAP to make changes in the code, and the victim needs to execute by using SAP GUI for Windows. This… | |
| Aplazada | Media (6.1) | 0.23% | — | SAP Netweaver Application Server AbapAI | 12/8/2025 | 17/6/2026 | SAP NetWeaver Application Server for ABAP has cross-site scripting vulnerability. Due to this, an unauthenticated attacker could craft a URL embedded with malicious script and trick an unauthenticated victim to click on it to execute the script. Upon successful exploitation, the attacker could access and modify… | |
| Aplazada | Media (4.1) | 0.13% | — | SAP Netweaver Application Server AbapAISAP Abap PlatformAI | 12/8/2025 | 17/6/2026 | The SAP NetWeaver Application Server ABAP and ABAP Platform Internet Communication Manager (ICM) permits authorized users with admin privileges and local access to log files to read sensitive information, resulting in information disclosure. This leads to high impact on the confidentiality of the application, with no… | |
| Analizada | Alta (7.5) | 0.42% | — | IBM Websphere Application Server | 7/8/2025 | 17/6/2026 | IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a remote attacker to bypass security restrictions caused by a failure to honor security configuration. | |
| Analizada | Alta (7.5) | 0.46% | — | IBM Websphere Application Server | 16/7/2025 | 17/6/2026 | IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 are vulnerable to a denial of service, caused by a stack-based overflow. An attacker can send a specially crafted request that cause the server to consume excessive memory resources. | |
| Aplazada | Media (6.1) | 0.23% | — | SAP Netweaver Application Server AbapAI | 8/7/2025 | 17/6/2026 | Due to an open redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft a URL link embedding a malicious script at a location not properly sanitized. When a victim clicks on this link, the script executes within the victim's browser, redirecting them to a site controlled… | |
| Aplazada | Baja (3.5) | 0.14% | — | SAP Netweaver Application Server JavaAI | 8/7/2025 | 17/6/2026 | The widely used component that establishes outbound TLS connections in SAP NetWeaver Application Server Java does not reliably match the hostname that is used for the connection against the wildcard hostname defined in the received certificate of remote TLS server. This might lead to the outbound connection being… | |
| Aplazada | Media (6.1) | 0.23% | — | SAP Netweaver Application Server AbapAISAP Abap PlatformAI | 8/7/2025 | 17/6/2026 | SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject a malicious script into a dynamically crafted URL. The victim, when tricked into clicking on this crafted URL unknowingly executes the malicious payload in their browser. On successful exploitation, the attacker can… | |
| Aplazada | Crítica (9.1) | 0.74% | — | SAP Netweaver Application Server FOR JavaAI | 8/7/2025 | 17/6/2026 | A critical vulnerability in SAP NetWeaver Application server for Java Log Viewer enables authenticated administrator users to exploit unsafe Java object deserialization. Successful exploitation can lead to full operating system compromise, granting attackers complete control over the affected system. This results in a… | |
| Aplazada | Media (4.9) | 0.33% | — | SAP Netweaver Application Server FOR AbapAI | 8/7/2025 | 17/6/2026 | Due to a missing authorization check in SAP NetWeaver Application server for ABAP, an authenticated user with high privileges could exploit the insufficient validation of user permissions to access sensitive database tables. By leveraging overly permissive access configurations, unauthorized reading of critical data… | |
| Analizada | Crítica (9.8) | 13% | — | IBM Websphere Application Server | 25/6/2025 | 17/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects. | |
| Analizada | Alta (7.6) | 0.24% | — | IBM Websphere Application Server | 14/5/2025 | 17/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Baja (2.7) | 0.34% | — | IBM Websphere Application Server | 22/4/2025 | 17/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Aplazada | Media (4.3) | 0.27% | — | SAP Netweaver Application Server AbapAI | 8/4/2025 | 17/6/2026 | A Missing Authorization Check vulnerability exists in the Virus Scanner Interface of SAP NetWeaver Application Server ABAP. Because of this, an attacker authenticated as a non-administrative user can initiate a transaction, allowing them to access but not modify non-sensitive data without further authorization and… | |
| Aplazada | Media (4.7) | 0.24% | — | SAP Netweaver Application Server AbapAI | 8/4/2025 | 17/6/2026 | SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an attacker, without requiring any privileges, to inject malicious JavaScript into a website. When a user visits the compromised page, the injected script… | |
| Aplazada | Alta (8.5) | 0.50% | — | SAP Netweaver Application Server AbapAI | 8/4/2025 | 17/6/2026 | In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, which can be used to expose credentials for a remote service. These credentials can then be further exploited to completely compromise the remote… | |
| Aplazada | Media (5.4) | 0.22% | — | SAP Netweaver Application Server JavaAI | 11/3/2025 | 17/6/2026 | User management functionality in SAP NetWeaver Application Server Java is vulnerable to Stored Cross-Site Scripting (XSS). This could enable an attacker to inject malicious payload that gets stored and executed when a user accesses the functionality, hence leading to information disclosure or unauthorized data… | |
| Aplazada | Media (6.1) | 0.24% | — | SAP Netweaver Application Server AbapAI | 11/3/2025 | 17/6/2026 | SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to DOM-basedCross-Site Scripting (XSS) vulnerability. This allows an attacker with no privileges, to craft a malicious web message that exploits WEBGUI functionality. On successful exploitation, the malicious JavaScript… | |
| Aplazada | Media (6.1) | 0.25% | — | SAP Netweaver Application Server AbapAI | 11/3/2025 | 17/6/2026 | SAP NetWeaver Application Server ABAP allows malicious scripts to be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application, but it can have some minor impact on its confidentiality and integrity. | |
| Aplazada | Media (4.3) | 0.26% | — | SAP Netweaver Application Server JavaAI | 11/2/2025 | 17/6/2026 | SAP NetWeaver Application Server Java allows an attacker to access an endpoint that can disclose information about deployed server components, including their XML definitions. This information should ideally be restricted to customer administrators, even though they may not need it. These XML files are not entirely… |