Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.9 CVE-2026-58237 WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit t… No fix yet Fix from $1,6002026-08-11 MEDIUM 5.5 CVE-2026-58236 SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing security controls on an internal cod… No fix yet Fix from $1,6002026-08-11 MEDIUM 6.3 CVE-2026-58235 SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer libraries that contain known… No fix yet Fix from $1,6002026-08-11 HIGH 7.0 CVE-2026-58230 SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially … No fix yet Fix from $1,9502026-08-11 HIGH 7.3 CVE-2026-44765 Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access… No fix yet Fix from $1,9502026-08-11 HIGH 7.3 CVE-2026-44764 Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted … No fix yet Fix from $1,9502026-08-11 HIGH 7.6 CVE-2026-44763 SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using s… No fix yet Fix from $1,9502026-08-11 CRITICAL 9.1 CVE-2026-44758 SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected fu… No fix yet Fix from $2,3002026-08-11 MEDIUM 5.3 CVE-2026-40130 SAP SAPSPrint Service has memory corruption vulnerabilities in the handling of certain commands. An unauthenticated attacker could send specially cra… No fix yet Fix from $1,6002026-08-11 CRITICAL 9.8 CVE-2026-34265 SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corr… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.3 CVE-2026-48161 react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contained malicious commits 7b79148d… No fix yet Fix from $2,3002026-08-10 HIGH 8.6 CVE-2025-30241 Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before passing it to sy… No fix yet Fix from $1,9502026-08-10 MEDIUM 5.1 CVE-2025-30240 The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By placing a crafted symbolic li… No fix yet Fix from $1,6002026-08-10 HIGH 8.5 CVE-2025-30239 In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data may allow an… No fix yet Fix from $1,9502026-08-10 HIGH 8.6 CVE-2025-30238 In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to execute higher-privileged oper… No fix yet Fix from $1,9502026-08-10 HIGH 8.7 CVE-2025-30237 The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not consistently enforced on certa… No fix yet Fix from $1,9502026-08-10 MEDIUM 5.4 CVE-2026-72918 Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.… No fix yet Fix from $1,6002026-08-10 MEDIUM 6.5 CVE-2026-73033 Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in the pageIntegritySubmission() method in src/integri… No fix yet Fix from $1,6002026-08-10 HIGH 7.8 CVE-2026-63622 A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnera… No fix yet Fix from $1,9502026-08-10 CRITICAL 9.3 CVE-2026-48160 react-tracked provides state usage tracking with Proxies. Between 2026-05-18 19:26:36 and 2026-05-19 15:22:45, the default branch contained malicious… No fix yet Fix from $2,3002026-08-10 HIGH 8.8 CVE-2026-18982 A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to es… No fix yet Fix from $1,9502026-08-10 HIGH 8.8 CVE-2026-18951 A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` manageme… No fix yet Fix from $1,9502026-08-10 HIGH 8.8 CVE-2026-18950 A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The sy… No fix yet Fix from $1,9502026-08-10 HIGH 8.8 CVE-2026-18949 A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit … No fix yet Fix from $1,9502026-08-10 CRITICAL 9.9 CVE-2026-18948 A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'd… No fix yet Fix from $2,3002026-08-10 HIGH 8.5 CVE-2026-18947 A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental endpoints. By sending a spec… No fix yet Fix from $1,9502026-08-10 MEDIUM 5.5 CVE-2026-18942 A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This code would be executed by … No fix yet Fix from $1,6002026-08-10 HIGH 7.7 CVE-2026-18941 A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is "no_auth," meaning no securi… No fix yet Fix from $1,9502026-08-10 HIGH 7.6 CVE-2026-18621 A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a maliciou… No fix yet Fix from $1,9502026-08-10 HIGH 7.1 CVE-2026-18620 A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServic… No fix yet Fix from $1,9502026-08-10