Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-40135 An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an authenticated attacker… Netweaver Application Server Abap Mitigation only Fix from $1,6002026-05-12 MEDIUM 6.1 CVE-2026-27682 Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages), a… Netweaver Application Server Abap Mitigation only Fix from $1,6002026-05-12 MEDIUM 6.5 CVE-2026-34264 During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user… Human Capital Management Mitigation only Fix from $1,6002026-04-14 MEDIUM 6.1 CVE-2026-34257 Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft malicious URL that, if access… Netweaver Application Server Abap Mitigation only Fix from $1,6002026-04-14 MEDIUM 6.5 CVE-2026-27679 Due to missing authorization checks in the SAP S/4HANA frontend OData Service (Manage Reference Structures), an attacker could update and delete chil… Manage Reference Structures Mitigation only Fix from $1,6002026-04-14 MEDIUM 6.1 CVE-2026-27674 Due to a Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java), an unauthenticated attacker could supply crafted in… Netweaver Application Server Java Mitigation only Fix from $1,6002026-04-14 MEDIUM 5.0 CVE-2026-27688 Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user privileges could read Database… Netweaver Application Server Abap Mitigation only Fix from $1,6002026-03-10 MEDIUM 6.4 CVE-2026-24316 SAP NetWeaver Application Server for ABAP provides an ABAP Report for testing purposes, which allows to send HTTP requests to arbitrary internal or e… Netweaver Application Server Abap Mitigation only Fix from $1,6002026-03-10 MEDIUM 6.4 CVE-2026-24309 Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function modul… Netweaver Application Server Abap Mitigation only Fix from $1,6002026-03-10 MEDIUM 6.1 CVE-2026-24328 SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect th… Business Server Pages Mitigation only Fix from $1,6002026-02-10 HIGH 7.7 CVE-2026-24322 SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allow… Solution Tools Plug In Mitigation only Fix from $1,9502026-02-10 MEDIUM 6.5 CVE-2026-24324 SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to execute a specific query in … Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002026-02-10 MEDIUM 6.1 CVE-2026-24323 The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters that are not sufficiently sa… Document Management System Mitigation only Fix from $1,6002026-02-10 MEDIUM 5.3 CVE-2026-24321 SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these open endpoints to retrieve sens… Commerce Cloud Mitigation only Fix from $1,6002026-02-10 HIGH 8.8 CVE-2026-23687 SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and … Sap Basis Mitigation only Fix from $1,9502026-02-10 HIGH 7.7 CVE-2026-23689 Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network acc… Advanced Planning And Optimization Mitigation only Fix from $1,9502026-02-10 MEDIUM 5.8 CVE-2026-24319 In SAP Business One, sensitive information is written to the application�s memory dump files without obfuscation. Gaining access to this information … Business One Mitigation only Fix from $1,6002026-02-10 MEDIUM 5.2 CVE-2026-24312 An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative user can bypass role restric… Sap Basis Mitigation only Fix from $1,6002026-02-10 CRITICAL 9.6 CVE-2026-0509 SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls with… Netweaver As Abap Kernel Mitigation only Fix from $2,3002026-02-10 HIGH 8.1 CVE-2026-0508 The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert malicious URL within the appli… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502026-02-10 MEDIUM 6.1 CVE-2026-0505 The BSP applications allow an unauthenticated user to manipulate user-controlled URL parameters that are not sufficiently validated. This could resul… Document Management System Mitigation only Fix from $1,6002026-02-10 MEDIUM 5.9 CVE-2026-23684 A race condition vulnerability exists in the SAP Commerce cloud. Because of this when an attacker adds products to a cart, it may result in a cart en… Commerce Cloud Mitigation only Fix from $1,6002026-02-10 CRITICAL 9.9 CVE-2026-0488 An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthoriz… Netweaver Application Server Abap Mitigation only Fix from $2,3002026-02-10 HIGH 7.5 CVE-2026-0485 SAP BusinessObjects BI Platform allows an unauthenticated attacker to send specially crafted requests that could cause the Content Management Server … Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502026-02-10 HIGH 7.5 CVE-2026-0490 SAP BusinessObjects BI Platform allows an unauthenticated attacker to craft a specific network request to the trusted endpoint that breaks the authen… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502026-02-10 MEDIUM 6.5 CVE-2026-0484 Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker could access a specific transa… Sap Basis Mitigation only Fix from $1,6002026-02-10 MEDIUM 6.1 CVE-2026-0514 Due to a Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious link. When an unsusp… Business Connector Mitigation only Fix from $1,6002026-01-13 MEDIUM 6.8 CVE-2025-42894 Due to a Path Traversal vulnerability in SAP Business Connector, an attacker authenticated as an administrator with adjacent access could read, write… Business Connector Mitigation only Fix from $1,6002025-11-11 MEDIUM 6.1 CVE-2025-42893 Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL that, if accessed by a victi… Business Connector Mitigation only Fix from $1,6002025-11-11 MEDIUM 6.8 CVE-2025-42892 Due to an OS Command Injection vulnerability in SAP Business Connector, an authenticated attacker with administrative access and adjacent network acc… Business Connector Mitigation only Fix from $1,6002025-11-11