Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2628▼ 312 respecto a la semana anterior
Críticas / altas1351▲ 89 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5)0.18%—SAP GUI FOR WindowsAISAP GuixtAI10/3/202617/6/2026
SAP GUI for Windows allows DLL files to be loaded from arbitrary directories within the application. An unauthenticated attacker could exploit this vulnerability by persuading a victim to place a malicious DLL within one of these directories. The malicious command is executed in the victim user's context provided…
AplazadaMedia (5.5)0.11%—SAP GUI FOR WindowsAI11/11/202517/6/2026
SAP GUI for Windows may allow a highly privileged user on the affected client PC to locally access sensitive information stored in process memory during runtime.This vulnerability has a high impact on confidentiality, with no impact on integrity and availability.
AplazadaMedia (4.5)0.32%—SAP GUI FOR WindowsAISAP Application Server AbapAI12/8/202517/6/2026
SAP GUI for Windows may allow the leak of NTML hashes when specific ABAP frontend services are called with UNC paths. For a successful attack, the attacker needs developer authorization in a specific Application Server ABAP to make changes in the code, and the victim needs to execute by using SAP GUI for Windows. This…
AplazadaMedia (5.6)0.14%—GuixtAISAP GUI FOR WindowsAI8/7/202517/6/2026
The GuiXT application, which is integrated with SAP GUI for Windows, uses obfuscation algorithms instead of secure symmetric ciphers for storing the credentials of an RFC user on the client PC. This leads to a high impact on confidentiality because any attacker who gains access to the user hive of this user�s windows…
AplazadaMedia (4.3)0.18%—SAP GUI FOR WindowsAIGuixtAI13/5/202517/6/2026
SAP GUI for Windows allows an unauthenticated attacker to exploit insecure obfuscation algorithms used by the GuiXT application to store user credentials. While this issue does not impact the Integrity or Availability of the application, it may have a Low impact on the Confidentiality of data.
AplazadaMedia (6)0.17%—SAP GUI FOR WindowsAISAP RFC ServiceAI11/2/202517/6/2026
SAP GUI for Windows & RFC service credentials are incorrectly stored in the memory of the program allowing an unauthenticated attacker to access information within systems, resulting in privilege escalation. On successful exploitation, this could result in disclosure of highly sensitive information. This has no impact…
AplazadaMedia (6)0.24%—SAP GUI FOR WindowsAI14/1/202517/6/2026
SAP GUI for Windows stores user input on the client PC to improve usability. Under very specific circumstances an attacker with administrative privileges or access to the victim�s user directory on the Operating System level would be able to read this data. Depending on the user input provided in transactions, the…
AnalizadaMedia (4.2)0.15%—SAP GUI FOR Windows9/7/202417/6/2026
Under certain conditions, the memory of SAP GUI for Windows contains the password used to log on to an SAP system, which might allow an attacker to get hold of the password and impersonate the affected user. As a result, it has a high impact on the confidentiality but there is no impact on the integrity and…
ModificadaCrítica (9.3)0.53%—SAP GUI FOR Windows9/5/202317/6/2026
SAP GUI for Windows - version 7.70, 8.0, allows an unauthorized attacker to gain NTLM authentication information of a victim by tricking it into clicking a prepared shortcut file. Depending on the authorizations of the victim, the attacker can read and modify potentially sensitive information after successful…
ModificadaAlta (7.8)0.22%—SAP GUI FOR Windows10/11/202117/6/2026
An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an attacker with sufficient privileges on the local client-side PC to obtain an equivalent of the user’s password. With this highly sensitive data leaked, the attacker would be able to logon to the…
ModificadaMedia (6.1)0.62%—SAP GUI FOR Windows11/5/202117/6/2026
In specific situations SAP GUI for Windows until and including 7.60 PL9, 7.70 PL0, forwards a user to specific malicious website which could contain malware or might lead to phishing attacks to steal credentials of the victim.
ModificadaCrítica (9.8)3.8%—SAP GUI FOR Windows23/3/201717/6/2026
SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABAP code, aka SAP Security Note 2407616.