Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.8) | 0.36% | — | SAP Netweaver Business ClientAI | 8/9/2026 | 9/9/2026 | SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content. When the application is next launched, the crafted content is… | |
| Modificada | Media (6.1) | 0.35% | — | SAP Netweaver Business Client FOR Html | 13/2/2024 | 17/6/2026 | SAP NWBC for HTML - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An unauthenticated attacker can inject malicious javascript to cause… | |
| Analizada | Media (6.5) | 0.52% | — | SAP Business Client | 14/9/2021 | 17/6/2026 | When an attacker manages to get access to the local memory, or the memory dump of a victim, for example by a social engineering attack, SAP Business Client versions - 7.0, 7.70, will allow him to read extremely sensitive data, such as credentials. This would allow the attacker to compromise the corresponding backend… | |
| Analizada | Alta (7.8) | 0.34% | — | SAP Business Client | 12/5/2020 | 17/6/2026 | SAP Business Client, version 7.0, allows an attacker after a successful social engineering attack to inject malicious code as a DLL file in untrusted directories that can be executed by the application, due to uncontrolled search path element. An attacker could thereby control the behavior of the application. | |
| Analizada | Alta (7.5) | 0.38% | — | SAP Business Client | 14/4/2020 | 17/6/2026 | SAP Business Client, versions 6.5, 7.0, does not perform necessary integrity checks which could be exploited by an attacker under certain conditions to modify the installer. | |
| Analizada | Alta (7.5) | 0.99% | — | SAP Business Client | 14/3/2018 | 17/6/2026 | Under certain conditions SAP Business Client 6.5 allows an attacker to access information which would otherwise be restricted. | |
| Modificada | Media (4.3) | 1.8% | — | SAP Netweaver Business Client FOR Html | 7/1/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in SAP NetWeaver Business Client (NWBC) for HTML 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) roundtrips parameter, aka SAP Security Note 2051285. | |
| Modificada | Media (4.3) | 1.2% | — | SAP Netweaver Business Client | 13/6/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the testcanvas node in SAP NetWeaver Business Client (NWBC) allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) sap-accessibility parameter. | |
| Modificada | Alta (9.3) | 6.1% | — | SAP Netweaver Business Client | 17/12/2010 | 16/6/2026 | Stack-based buffer overflow in the SapThemeRepository ActiveX control (sapwdpcd.dll) in SAP NetWeaver Business Client allows remote attackers to execute arbitrary code via the (1) Load and (2) LoadTheme methods. |