Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
203 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.3) | 0.34% | — | SAP S/4hanaAI | 8/9/2026 | 8/9/2026 | SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send specially crafted requests to delete specific entries that should not be accessible to them. This results in a low impact on availability. There is no… | |
| Pendiente de análisis | Baja (3.5) | 0.14% | — | SAP S/4hana FinanceAI | 8/9/2026 | 9/9/2026 | SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web… | |
| Pendiente de análisis | Baja (3.5) | 0.14% | — | SAP S/4hana FinanceAI | 8/9/2026 | 8/9/2026 | SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web… | |
| Pendiente de análisis | Media (4.6) | 0.13% | — | SAP S/4hana FinanceAI | 8/9/2026 | 8/9/2026 | SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server… | |
| Pendiente de análisis | Media (6.5) | 0.39% | — | SAP S/4hanaAI | 8/9/2026 | 8/9/2026 | SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed by the database without proper validation. This could allow the user to access sensitive information, resulting in high impact on confidentiality,… | |
| Pendiente de análisis | Alta (7.5) | 0.51% | — | SAP S/4hanaAI | 25/8/2026 | 26/8/2026 | SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnerability. An unauthenticated attacker could supply specially crafted input that triggers excessive processing within the affected functionality. Successful exploitation could exhaust system… | |
| Pendiente de análisis | Media (4.3) | 0.28% | — | SAP S/4hanaAI | 11/8/2026 | 26/8/2026 | Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated users, allowing them to use rules that have not been shared with them, resulting in privilege escalation.This vulnerability has a low impact on confidentiality, with no impact on integrity and… | |
| Pendiente de análisis | Media (4.3) | 0.28% | — | SAP S/4hanaAI | 14/7/2026 | 14/7/2026 | SAP S/4HANA Draft operation does not perform necessary authorization checks for an authenticated user, a restricted user could access information within the entity resulting in escalation of privileges. This results in low impact on confidentiality, with no impact on integrity and availability of the application. | |
| Pendiente de análisis | Media (5.5) | 0.31% | — | SAP S/4hanaAI | 14/7/2026 | 14/7/2026 | SAP S/4HANA application Project Management (PPM-PRO) allows an attacker with high privileges to execute crafted database queries, exposing the backend database. This results in low impact on confidentiality, with no impact on integrity and availability of the application. | |
| Pendiente de análisis | Baja (3.7) | 0.35% | — | SAP Hana DatabaseAI | 14/7/2026 | 14/7/2026 | SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produce distinguishable responses, enabling enumeration of valid user accounts and email addresses. Successful exploitation could allow the attacker to enumerate valid user accounts, resulting in low… | |
| Pendiente de análisis | Media (6.5) | 0.38% | — | SAP S/4hanaAI | 9/6/2026 | 23/7/2026 | SAP S/4HANA(On-Premise) contains SQL injection vulnerability in a remote-enabled function module component that could be exploited by an authenticated attacker to potentially execute unauthorized database queries.This flaw exposes sensitive information to which they should not otherwise have access to. The… | |
| Pendiente de análisis | Media (6.3) | 0.27% | — | SAP S/4hanaAI | 12/5/2026 | 17/6/2026 | Due to missing authorization check in SAP S/4HANA Condition Maintenance, an authenticated attacker could gain unauthorized access to view and modify condition table records, resulting in low impact on the confidentiality and integrity of the data. Additionally, this vulnerability may prevent the legitimate user from… | |
| Pendiente de análisis | Crítica (9.6) | 0.43% | — | SAP S/4hanaAI | 12/5/2026 | 17/6/2026 | SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to inject malicious SQL statements through user-controlled input. The application directly concatenates this malicious user input into SQL queries, which are then passed to the underlying database… | |
| Analizada | Media (4.3) | 0.35% | — | SAP Hana CockpitSAP Hana Database Explorer | 14/4/2026 | 17/6/2026 | Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer | |
| Pendiente de análisis | Alta (7.1) | 0.34% | — | SAP ERPAISAP S/4hanaAI | 14/4/2026 | 17/6/2026 | Due to a missing authorization check in SAP ERP and SAP S/4HANA (Private Cloud and On-Premise), an authenticated attacker could execute a particular ABAP report to overwrite any existing eight?character executable ABAP report without authorization. If the overwritten report is subsequently executed, the intended… | |
| Pendiente de análisis | Media (6.5) | 0.31% | — | SAP S/4hanaAI | 14/4/2026 | 17/6/2026 | Due to missing authorization checks in the SAP S/4HANA backend OData Service (Manage Reference Structures), an attacker could update and delete child entities via exposed OData services without proper authorization. This vulnerability has a high impact on integrity, while confidentiality and availability are not… | |
| Pendiente de análisis | Media (6.5) | 0.31% | — | SAP S/4hanaAI | 14/4/2026 | 17/6/2026 | Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Reference Equipment), an attacker could update and delete child entities via OData services without proper authorization. This vulnerability has a high impact on integrity, while confidentiality and availability are not impacted. | |
| Pendiente de análisis | Media (4.3) | 0.26% | — | SAP S/4hanaAI | 14/4/2026 | 17/6/2026 | Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Technical Object Structures), an attacker could update and delete child entities via exposed OData services without proper authorization. This vulnerability results in a low impact on integrity, while confidentiality and availability are not… | |
| Pendiente de análisis | Media (4.9) | 0.25% | — | SAP S/4hanaAI | 14/4/2026 | 17/6/2026 | Due to a missing authorization check, SAP S/4HANA (Private Cloud and On-Premise) allows an authenticated user to delete files on the operating system and gain unauthorized control over file operations which could leads to no impact on Confidentiality, Low impact on Integrity and Availability of the application. | |
| Pendiente de análisis | Media (5.8) | 0.33% | — | SAP S/4hana HCM PortugalAISAP ERP HCM PortugalAI | 10/3/2026 | 17/6/2026 | Due to missing authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal, a user with high privileges could access sensitive data belonging to another company. This vulnerability has a high impact on confidentiality and does not affect integrity and availability. | |
| Analizada | Media (4.3) | 0.20% | — | SAP S/4hana Uiapfi70SAP S/4hana Uis4h | 24/2/2026 | 17/6/2026 | Under certain conditions SAP S/4HANA (Manage Payment Media) allows an authenticated attacker to access information which would otherwise be restricted. This could cause low impact on confidentiality of the application while integrity and availability are not impacted. | |
| Analizada | Media (4.3) | 0.21% | — | SAP S/4hana Defense & Security | 10/2/2026 | 17/6/2026 | Due to a missing authorization check in the Disconnected Operations of the SAP S/4HANA Defense & Security, an attacker with user privileges could call remote-enabled function modules to do direct update on standard SAP database table . This results in low impact on integrity, with no impact on confidentiality or… | |
| Analizada | Crítica (9.9) | 0.52% | — | SAP Netweaver Application Server AbapSAP S/4hanaSAP Webclient UI Framework | 10/2/2026 | 17/6/2026 | An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impact on… | |
| Aplazada | Media (6.4) | 0.23% | — | SAP ERP Central ComponentAISAP EHS ManagementAISAP S/4hanaAI | 13/1/2026 | 17/6/2026 | Due to missing authorization check in the SAP ERP Central Component (SAP ECC) and SAP S/4HANA (SAP EHS Management), an attacker could extract hardcoded clear-text credentials and bypass the password authentication check by manipulating user parameters. Upon successful exploitation, the attacker can access, modify or… | |
| Aplazada | Crítica (9.9) | 0.47% | — | SAP S/4hanaAI | 13/1/2026 | 17/6/2026 | Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authenticated user could execute crafted SQL queries to read, modify, and delete backend database data. This leads to a high impact on the confidentiality, integrity, and availability of the application. |