Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
201 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.3% | — | SAP Abap PlatformSAP Netweaver Application Server Abap | 12/8/2020 | 17/6/2026 | SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject code that can be executed by the application, leading to Code Injection. An attacker could thereby control the behavior of the application. | |
| Modificada | Baja (2.7) | 0.94% | — | SAP Abap PlatformSAP Netweaver Application Server Abap | 14/7/2020 | 17/6/2026 | SAP NetWeaver (ABAP Server) and ABAP Platform, versions 731, 740, 750, allows an attacker with admin privileges to access certain files which should otherwise be restricted, leading to Information Disclosure. | |
| Modificada | Crítica (9.8) | 1.4% | — | SAP Netweaver Application Server Abap | 10/6/2020 | 17/6/2026 | SAP Netweaver AS ABAP, versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, are vulnerable for Server Side Request Forgery Attack where in an attacker can use inappropriate path names containing malicious server names in the import/export of sessions functionality and coerce the web server into… | |
| Modificada | Media (6.5) | 0.80% | — | SAP Netweaver Application Server Abap | 10/6/2020 | 17/6/2026 | SAP NetWeaver AS ABAP (Banking Services), versions - 710, 711, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not perform necessary authorization checks for an authenticated user due to Missing Authorization Check, allowing wrong and unexpected change of individual conditions by a malicious user leading to wrong… | |
| Modificada | Media (6.1) | 0.65% | — | SAP Netweaver AS Abap Business Server Pages | 10/6/2020 | 17/6/2026 | SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_TABLE, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Alta (7.5) | 1.4% | — | SAP Netweaver Application Server Abap | 12/5/2020 | 17/6/2026 | SAP NetWeaver AS ABAP (Web Dynpro ABAP), versions (SAP_UI 750, 752, 753, 754 and SAP_BASIS 700, 710, 730, 731, 804) allows an unauthenticated attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service leading to Denial of Service | |
| Modificada | Media (6.1) | 0.80% | — | SAP Netweaver AS Abap Business Server Pages | 24/4/2020 | 17/6/2026 | SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_PHTMLB, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, is vulnerable to reflected Cross-Site Scripting (XSS) via different URL parameters as it does not sufficiently encode user controlled inputs. | |
| Modificada | Media (6.1) | 0.65% | — | SAP Netweaver AS Abap Business Server Pages | 14/4/2020 | 17/6/2026 | SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Media (6.1) | 1.6% | — | SAP Netweaver AS Abap Business Server Pages | 14/4/2020 | 17/6/2026 | SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal credentials of the victim, leading to URL Redirection vulnerability. | |
| Modificada | Media (6.1) | 0.65% | — | SAP Netweaver AS Abap Business Server Pages | 14/4/2020 | 17/6/2026 | SAP NetWeaver AS ABAP (Business Server Pages application CRM_BSP_FRAME), versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not sufficiently encode user controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Media (6.1) | 0.77% | — | SAP Netweaver AS Abap Business Server Pages | 10/3/2020 | 17/6/2026 | SAP NetWeaver AS ABAP Business Server Pages (Smart Forms), SAP_BASIS versions- 7.00, 7.01, 7.02, 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, 7.51, 7.52, 7.53, 7.54; does not sufficiently encode user controlled inputs, allowing an unauthenticated attacker to non-permanently deface or modify displayed content and/or steal… | |
| Modificada | Media (5.8) | 0.78% | — | SAP Abap PlatformSAP Netweaver | 12/2/2020 | 17/6/2026 | Under some circumstances the SAML SSO implementation in the SAP NetWeaver (SAP_BASIS versions 702, 730, 731, 740 and SAP ABAP Platform (SAP_BASIS versions 750, 751, 752, 753, 754), allows an attacker to include invalidated data in the HTTP response header sent to a Web user, leading to HTTP Response Splitting… | |
| Modificada | Media (6.1) | 1.3% | — | SAP Netweaver Application Server AbapSAP Netweaver AS Abap | 10/7/2019 | 17/6/2026 | ABAP Server and ABAP Platform (SAP Basis), versions, 7.31, 7.4, 7.5, do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Alta (8.8) | 1.4% | — | SAP Netweaver Application Server AbapSAP Netweaver AS Abap | 15/2/2019 | 17/6/2026 | Customizing functionality of SAP NetWeaver AS ABAP Platform (fixed in versions from 7.0 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.53, from 7.74 to 7.75) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. | |
| Modificada | Alta (8.8) | 5.0% | 💥 Exploit | Labapart Gattlib | 21/1/2019 | 17/6/2026 | GattLib 0.2 has a stack-based buffer over-read in gattlib_connect in dbus/gattlib.c because strncpy is misused. | |
| Modificada | Media (4.8) | 0.59% | — | Grabaperch Perch | 28/10/2017 | 17/6/2026 | Perch Content Management System 3.0.3 allows unrestricted file upload (with resultant XSS) via the Asset Title field in conjunction with the Select File field. This is exploitable with a Limited Admin account. | |
| Modificada | Baja (2.7) | 2.3% | — | SAP Netweaver Abap | 12/7/2017 | 17/6/2026 | SAP NetWeaver AS ABAP 7.40 allows remote authenticated users with certain privileges to cause a denial of service (process crash) via vectors involving disp+work.exe, aka SAP Security Note 2406841. | |
| Modificada | Media (5) | 1.8% | — | SAP Netweaver Abap Application ServerSAP Netweaver Java Application Server | 2/6/2015 | 17/6/2026 | SAP ABAP & Java Server allows remote attackers to cause a denial of service (service termination) via unspecified vectors, aka SAP Security Note 2121661. | |
| Modificada | Alta (7.5) | 3.5% | — | SAP GUISAP MaxdbSAP Netweaver Abap Application ServerSAP Netweaver Java Application Server+2 | 2/6/2015 | 17/6/2026 | Stack-based buffer overflow in the LZC decompression implementation (CsObjectInt::CsDecomprLZC function in vpa106cslzc.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Server Java, Netweaver RFC SDK, GUI, RFC SDK, SAPCAR archive tool, and other products allows context-dependent… | |
| Modificada | Media (5) | 2.1% | — | SAP GUISAP MaxdbSAP Netweaver Abap Application ServerSAP Netweaver Java Application Server+2 | 2/6/2015 | 17/6/2026 | The LZH decompression implementation (CsObjectInt::BuildHufTree function in vpa108csulzh.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Server Java, Netweaver RFC SDK, GUI, RFC SDK, SAPCAR archive tool, and other products allows context-dependent attackers to cause a denial of… | |
| Modificada | Media (5) | 2.2% | — | SAP Netweaver Abap | 22/1/2015 | 17/6/2026 | XML external entity vulnerability in the Extended Computer Aided Test Tool (eCATT) in SAP NetWeaver AS ABAP 7.31 and earlier allows remote attackers to access arbitrary files via a crafted XML request, related to ECATT_DISPLAY_XMLSTRING_REMOTE, aka SAP Note 2016638. | |
| Modificada | Baja (3.5) | 2.1% | — | SAP Netweaver Abap | 16/10/2014 | 17/6/2026 | Business Warehouse (BW) in SAP Netweaver AS ABAP 7.31 allows remote authenticated users to obtain sensitive information via a request to the RSDU_CCMS_GET_PROFILE_PARAM RFC function. | |
| Modificada | Media (5.4) | 0.27% | — | Grabapp Eponyms | 20/9/2014 | 17/6/2026 | The eponyms (aka com.anddeveloper.eponyms) application 3.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.6) | 0.33% | — | SAP Netweaver Abap Application Server | 30/4/2014 | 17/6/2026 | The ABAP Help documentation and translation tools (BC-DOC-HLP) in Basis in SAP Netweaver ABAP Application Server does not properly restrict access, which allows local users to gain privileges and execute ABAP instructions via crafted help messages. | |
| Modificada | Alta (7.5) | 1.5% | — | SAP Business Object Processing Framework FOR Abap | 10/4/2014 | 17/6/2026 | SAP Business Object Processing Framework (BOPF) for ABAP has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. |