Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2020-26825
SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to use SAP Fiori Launchpad News tile…
Fiori Launchpad \(news Tile Application\)
Mitigation only
CRITICAL 10.0
CVE-2020-26821
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization check…
Solution Manager
Mitigation only
CRITICAL 10.0
CVE-2020-26822
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization check…
Solution Manager
Mitigation only
CRITICAL 10.0
CVE-2020-26823
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization check…
Solution Manager
Mitigation only
CRITICAL 10.0
CVE-2020-26824
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization check…
Solution Manager
Mitigation only
HIGH 8.8
CVE-2020-26819
SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro compone…
Netweaver Application Server Abap
Mitigation only
HIGH 7.2
CVE-2020-26820
SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator …
Netweaver Application Server Java
No fix yet
HIGH 8.8
CVE-2020-26818
SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro compone…
Netweaver Application Server Abap
Mitigation only
HIGH 8.6
CVE-2020-26815
SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send a crafted request to a vulne…
Fiori Launchpad \(news Tile Application\)
Mitigation only
HIGH 7.8
CVE-2020-26817
SAP 3D Visual Enterprise Viewer, version - 9, allows an user to open manipulated HPGL file received from untrusted sources which results in crashing …
3d Visual Enterprise Viewer
Mitigation only
HIGH 7.5
CVE-2020-26810
SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over…
Commerce Cloud \(accelerator Payment Mock\)
Mitigation only
HIGH 7.2
CVE-2020-26808
SAP AS ABAP(DMIS), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA(DMIS), version…
Sap As Abap\(dmis\)
No fix yet
MEDIUM 5.3
CVE-2020-26809
SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the '/medias' endpo…
Commerce Cloud
No fix yet
MEDIUM 5.3
CVE-2020-26811
SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over…
Commerce Cloud \(accelerator Payment Mock\)
No fix yet
MEDIUM 6.5
CVE-2020-6362
SAP Banking Services version 500, use an incorrect authorization object in some of its reports. Although the affected reports are protected with othe…
Banking Services
Mitigation only
MEDIUM 6.5
CVE-2020-6366
SAP NetWeaver (Compare Systems) versions - 7.20, 7.30, 7.40, 7.50, does not sufficiently validate uploaded XML documents. An attacker with administra…
Netweaver Compare Systems
Mitigation only
MEDIUM 6.1
CVE-2020-6367
There is a reflected cross site scripting vulnerability in SAP NetWeaver Composite Application Framework, versions - 7.20, 7.30, 7.31, 7.40, 7.50. An…
Netweaver Composite Application Framework
Mitigation only
MEDIUM 5.9
CVE-2020-6369
SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an unauthenticated attackers to byp…
Focused Run
No fix yet
MEDIUM 5.5
CVE-2020-6315
SAP 3D Visual Enterprise Viewer, version 9, allows an attacker to send certain manipulated file to the victim, which can lead to leakage of sensitive…
3d Visual Enterprise Viewer
Mitigation only
MEDIUM 5.3
CVE-2020-6308EPSS 62%
SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary va…
Businessobjects Business Intelligence Platform
Mitigation only
MEDIUM 6.1
CVE-2020-6365
SAP NetWeaver AS Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, Start Page allows an unauthenticated remote attacker to redirect users to…
Netweaver Application Server Java
Mitigation only
HIGH 7.8
CVE-2020-6372
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources which results in crashing of…
3d Visual Enterprise Viewer
Mitigation only
HIGH 7.8
CVE-2020-6373
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources which results in crashing of…
3d Visual Enterprise Viewer
Mitigation only
HIGH 7.8
CVE-2020-6374
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Jupiter Tessallation(.jt) file received from untrusted sources which …
3d Visual Enterprise Viewer
Mitigation only
MEDIUM 5.5
CVE-2020-6375
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Right Computer Graphics Metafile (.cgm) file received from untrusted …
3d Visual Enterprise Viewer
Mitigation only
MEDIUM 5.5
CVE-2020-6376
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Right Hemisphere Binary (.rh) file received from untrusted sources wh…
3d Visual Enterprise Viewer
Mitigation only
CRITICAL 10.0
CVE-2020-6364EPSS 6%
SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an attacker to modify a cookie in a…
Introscope Enterprise Manager
Mitigation only
MEDIUM 6.1
CVE-2020-6319
SAP NetWeaver Application Server Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 allows an unauthenticated attacker to include JavaScri…
Netweaver Application Server Java
Mitigation only
MEDIUM 6.1
CVE-2020-6323
SAP NetWeaver Enterprise Portal (Fiori Framework Page) versions - 7.50, 7.31, 7.40, does not sufficiently encode user-controlled inputs and allows an…
Netweaver Enterprise Portal
Mitigation only
MEDIUM 5.4
CVE-2020-6272
SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated and authorized content …
Commerce Cloud
Mitigation only