Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.5
CVE-2026-58248

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file…

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 5.3
CVE-2026-58247

SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This could disclose limited, non-sensi…

No fix yet
Fix from $1,600 2026-08-11
Unclassified HIGH 8.8
CVE-2026-58243

SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to exe…

No fix yet
Fix from $1,950 2026-08-11
Unclassified MEDIUM 5.9
CVE-2026-58238

SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input…

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 5.9
CVE-2026-58237

WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit t…

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 5.5
CVE-2026-58236

SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing security controls on an internal cod…

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 6.3
CVE-2026-58235

SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer libraries that contain known…

No fix yet
Fix from $1,600 2026-08-11
Unclassified HIGH 7.0
CVE-2026-58230

SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially …

No fix yet
Fix from $1,950 2026-08-11
Unclassified HIGH 7.3
CVE-2026-44765

Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access…

No fix yet
Fix from $1,950 2026-08-11
Unclassified HIGH 7.3
CVE-2026-44764

Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted …

No fix yet
Fix from $1,950 2026-08-11
Unclassified HIGH 7.6
CVE-2026-44763

SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using s…

No fix yet
Fix from $1,950 2026-08-11
Unclassified CRITICAL 9.1
CVE-2026-44758

SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected fu…

No fix yet
Fix from $2,300 2026-08-11
Unclassified MEDIUM 5.3
CVE-2026-40130

SAP SAPSPrint Service has memory corruption vulnerabilities in the handling of certain commands. An unauthenticated attacker could send specially cra…

No fix yet
Fix from $1,600 2026-08-11
Unclassified CRITICAL 9.8
CVE-2026-34265

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corr…

No fix yet
Fix from $2,300 2026-08-11
Unclassified HIGH 8.4
CVE-2026-8718

tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), pass…

Patch available
Fix from $1,950 2026-08-10
Unclassified CRITICAL 9.3
CVE-2026-48161

react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contained malicious commits 7b79148d…

No fix yet
Fix from $2,300 2026-08-10
Unclassified HIGH 8.6
CVE-2025-30241

Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before passing it to sy…

No fix yet
Fix from $1,950 2026-08-10
Unclassified MEDIUM 5.1
CVE-2025-30240

The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By placing a crafted symbolic li…

No fix yet
Fix from $1,600 2026-08-10
Unclassified HIGH 8.5
CVE-2025-30239

In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data may allow an…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 8.6
CVE-2025-30238

In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to execute higher-privileged oper…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 8.7
CVE-2025-30237

The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not consistently enforced on certa…

No fix yet
Fix from $1,950 2026-08-10
Unclassified MEDIUM 5.4
CVE-2026-72918

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.…

No fix yet
Fix from $1,600 2026-08-10
Unclassified MEDIUM 5.9
CVE-2026-72917

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.0.0 to 1.15.0, Any…

Patch available
Fix from $1,600 2026-08-10
Unclassified MEDIUM 6.3
CVE-2026-72916

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, PrivateAddressCheck.pri…

Patch available
Fix from $1,600 2026-08-10
Unclassified HIGH 7.5
CVE-2026-72915

Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta.1, any logged-in local user …

Patch available
Fix from $1,950 2026-08-10
Unclassified HIGH 7.5
CVE-2026-72914

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, the administrative stat…

Patch available
Fix from $1,950 2026-08-10
Unclassified MEDIUM 6.5
CVE-2026-73033

Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in the pageIntegritySubmission() method in src/integri…

No fix yet
Fix from $1,600 2026-08-10
Unclassified HIGH 8.1
CVE-2026-73030

unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize …

Patch available
Fix from $1,950 2026-08-10
Unclassified HIGH 7.3
CVE-2026-72913

Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/window.py write unauthenticated d…

Patch available
Fix from $1,950 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72911

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls i…

Patch available
Fix from $2,300 2026-08-10