Search
13,075 CVEs
EOL hidden · Show all products
CVEs (13,075, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 151–175 of 13,075 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-82710 | NONE | Patched | — | 2026-09-08 | Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project usage_rules allows a malicious package publisher to inject terminal control seque… |
| CVE-2026-76977 | MEDIUM | 4.3 | 2026-09-08 | SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated attacker could host a malicious page to bypass framing… | |
| CVE-2026-76971 | MEDIUM | 6.5 | 2026-09-08 | Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker could cause the server to initiate arbitrary outbou… | |
| CVE-2026-76969 | CRITICAL | 9.4 | 2026-09-08 | @sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated at… | |
| CVE-2026-76968 | MEDIUM | 6.5 | 2026-09-08 | SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or … | |
| CVE-2026-76967 | HIGH | 7.8 | 2026-09-08 | SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges… | |
| CVE-2026-76963 | MEDIUM | 4.3 | 2026-09-08 | Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive sy… | |
| CVE-2026-76962 | MEDIUM | 4.3 | 2026-09-08 | SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send spec… | |
| CVE-2026-76961 | LOW | 3.5 | 2026-09-08 | SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low pr… | |
| CVE-2026-76960 | LOW | 3.5 | 2026-09-08 | SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low pr… | |
| CVE-2026-76959 | MEDIUM | 4.6 | 2026-09-08 | SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests due to this an attacker with low pri… | |
| CVE-2026-76958 | HIGH | 8.5 | 2026-09-08 | SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could sub… | |
| CVE-2026-66768 | CRITICAL | 9.0 | 2026-09-08 | SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit th… | |
| CVE-2026-66767 | HIGH | 7.7 | 2026-09-08 | SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buf… | |
| CVE-2026-58240 | CRITICAL | 9.8 | 2026-09-08 | SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with… | |
| CVE-2026-58234 | LOW | 2.2 | 2026-09-08 | SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nested entity definitions, which under certain conditio… | |
| CVE-2026-44766 | MEDIUM | 6.5 | 2026-09-08 | SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed b… | |
| CVE-2026-44756 | CRITICAL | 10.0 | 2026-09-08 | A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a craf… | |
| CVE-2026-86544 | HIGH | Patched | 8.1 | 2026-09-07 | knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with r… |
| CVE-2026-86543 | CRITICAL | Patched | 9.8 | 2026-09-07 | knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attack… |
| CVE-2026-86542 | CRITICAL | Patched | 9.1 | 2026-09-07 | knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can sup… |
| CVE-2026-86541 | HIGH | Patched | 8.3 | 2026-09-07 | knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the proj… |
| CVE-2026-86540 | HIGH | Patched | 7.8 | 2026-09-07 | knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by c… |
| CVE-2026-86539 | HIGH | 7.2 | 2026-09-07 | knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied … | |
| CVE-2026-86538 | HIGH | Patched | 7.5 | 2026-09-07 | knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary fil… |