Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2751▲ 74 respecto a la semana anterior
Críticas / altas1464▲ 358 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)89▼ 424 respecto a la semana anterior
–

2261 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.8)——SaplingAI2/10/20262/10/2026
In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed repository, if cloned by a target, could trigger code execution on otherwise read-only actions such as sl log/blame/annotate.
AplazadaAlta (7.2)0.27%—Openclaw WhatsappAI26/9/202629/9/2026
@openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the originating sender's owner status, so the owner-only tool boundary is not enforced. An admitted non-owner sender able to steer the tool can request a forced login and receive a new QR…
AplazadaAlta (7.3)0.39%—Opentext Vendor Invoice Management FOR SAP SolutionsAI24/9/202624/9/2026
A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. Under certain conditions, this issue could allow execution of unauthorized script content in a user's browser, potentially impacting confidentiality and…
Pendiente de análisisMedia (5.3)0.35%—SAP Fiori LaunchpadAI21/9/202622/9/2026
SAP Fiori Launchpad does not sufficiently validate certain user-controlled input. An unauthenticated attacker could craft a malicious link that, when clicked by an authenticated user, causes the browser to load attacker-controlled content from an external location. This could be used to exfiltrate sensitive…
AplazadaMedia (5.3)0.45%—Governikus AusweisappAI15/9/202616/9/2026
A weakness has been identified in Governikus AusweisApp up to 2.5.4. Affected is an unknown function of the component StartPAOSResponse Handler. Executing a manipulation of the argument ResultMessage can lead to cross site scripting. The attack can be launched remotely. Upgrading to version 2.5.5 is able to address…
Pendiente de análisisMedia (4.3)0.37%—SAP UI5AI8/9/20268/9/2026
SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated attacker could host a malicious page to bypass framing restrictions. If an authenticated victim visits the attacker's page and interacts with it, the attacker could trick the victim into performing…
Pendiente de análisisMedia (6.5)0.25%—SAP Manufacturing Integration AND IntelligenceAI8/9/20268/9/2026
Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker could cause the server to initiate arbitrary outbound requests. If processed by the application, this behavior could be combined with XML/XSL processing to enable execution of scripts. Successful…
Pendiente de análisisCrítica (9.4)0.44%—SAP Cds-mtxsAI8/9/20268/9/2026
@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credentials and abuse them to replace or delete tenant data. Successful…
Pendiente de análisisMedia (6.5)0.39%—SAP WEB DispatcherAISAP Internet Communication ManagerAISAP Content ServerAI8/9/20268/9/2026
SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could…
Pendiente de análisisAlta (7.8)0.36%—SAP Netweaver Business ClientAI8/9/20269/9/2026
SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content. When the application is next launched, the crafted content is…
Pendiente de análisisMedia (4.3)0.28%—SAP NetweaverAISAP Abap PlatformAI8/9/20268/9/2026
Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive system configuration information. Successful exploitation could result in exposure of security relevant settings and internal system details,…
Pendiente de análisisMedia (4.3)0.34%—SAP S/4hanaAI8/9/20268/9/2026
SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send specially crafted requests to delete specific entries that should not be accessible to them. This results in a low impact on availability. There is no…
Pendiente de análisisBaja (3.5)0.14%—SAP S/4hana FinanceAI8/9/20269/9/2026
SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web…
Pendiente de análisisBaja (3.5)0.14%—SAP S/4hana FinanceAI8/9/20268/9/2026
SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web…
Pendiente de análisisMedia (4.6)0.13%—SAP S/4hana FinanceAI8/9/20268/9/2026
SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server…
Pendiente de análisisAlta (8.5)0.38%—SAP Integration SuiteAI8/9/20268/9/2026
SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML payloads containing malicious external entity declarations. Successful exploitation could allow the attacker to read…
Pendiente de análisisCrítica (9)0.61%—SAP GUI FOR JavaAI8/9/20269/9/2026
SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. This could allow arbitrary command execution on the…
Pendiente de análisisAlta (7.7)0.43%—SAP Netweaver Application Server FOR AbapAISAP Abap PlatformAI8/9/20269/9/2026
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could result in high…
Pendiente de análisisCrítica (9.8)0.53%—SAP Netweaver Message ServerAI8/9/20269/9/2026
SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized…
Pendiente de análisisBaja (2.2)0.34%—SAP Process IntegrationAI8/9/20268/9/2026
SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nested entity definitions, which under certain conditions could temporarily increase processor load and degrade system responsiveness. Successful exploitation results in low impact on availability with…
Pendiente de análisisMedia (6.5)0.39%—SAP S/4hanaAI8/9/20268/9/2026
SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed by the database without proper validation. This could allow the user to access sensitive information, resulting in high impact on confidentiality,…
AplazadaMedia (4.6)0.29%—Wallosapp WallosAI31/8/20268/9/2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos allows authenticated users to inject arbitrary iCalendar properties and events into their exported .ics feed by embedding raw CRLF sequences in subscription names or notes. Because the input validation layer only…
AplazadaMedia (4.3)0.33%—Wallosapp WallosAI31/8/20268/9/2026
Wallos is an open-source, self-hostable personal subscription tracker. From version 2.0.0 to before version 5.0.0, any authenticated Wallos user (no admin rights required) can make the server open arbitrary outbound SMTP connections to internal/link-local addresses, by setting the SMTP host of their personal email…
AplazadaBaja (3.5)0.29%—PhpmailerAIWallosapp WallosAI31/8/20268/9/2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos lets any authenticated user store an arbitrary SMTP host — including private and cloud-metadata IP addresses — in their personal email notification settings, with no server-side SSRF validation. When the scheduled…
AplazadaAlta (8.2)0.43%—Wallosapp WallosAI31/8/20268/9/2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment Variable") hardened endpoints/logos/search.php by disabling cURL proxying (CURLOPT_PROXY = '' + CURLOPT_NOPROXY = '*'). However, Wallos ships…