Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2025-42886
Due to a Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could generate a malicious link an…
Business Connector
Mitigation only
CRITICAL 9.1
CVE-2025-42999 KEVEPSS 12%
SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserializ…
Netweaver
Mitigation only
CRITICAL 9.8
CVE-2025-30012
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component, which allows an unauthenticated attac…
Supplier Relationship Management
Mitigation only
HIGH 7.5
CVE-2025-30018
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an application servlet request wi…
Supplier Relationship Management
Mitigation only
MEDIUM 6.1
CVE-2025-30009
he Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which …
Supplier Relationship Management
Mitigation only
MEDIUM 6.1
CVE-2025-30010
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which…
Supplier Relationship Management
Mitigation only
MEDIUM 5.3
CVE-2025-30011
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which…
Supplier Relationship Management
Mitigation only
CRITICAL 9.8
CVE-2025-31324 KEVEPSS 100%
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially ma…
Netweaver
Mitigation only
HIGH 7.1
CVE-2025-31332
Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker who has local access to the system could modify f…
Businessobjects Business Intelligence Platform
Mitigation only
HIGH 7.1
CVE-2024-47595
An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access. On successful exploitation t…
Host Agent
Mitigation only
MEDIUM 5.4
CVE-2024-47594
SAP NetWeaver Enterprise Portal (KMC) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability in KMC ser…
Netweaver Enterprise Portal
Mitigation only
MEDIUM 5.4
CVE-2024-45278
SAP Commerce Backoffice does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful …
Commerce Backoffice
Mitigation only
MEDIUM 5.3
CVE-2024-45282
Fields which are in 'read only' state in Bank Statement Draft in Manage Bank Statements application, could be modified by MERGE method. The property …
S\/4 Hana
Mitigation only
MEDIUM 6.5
CVE-2024-37179
SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting…
Businessobjects Business Intelligence
Mitigation only
MEDIUM 5.4
CVE-2024-42373
SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of…
Student Life Cycle Management
Mitigation only
MEDIUM 5.3
CVE-2024-39591
SAP Document Builder does not perform necessary authorization checks for one of the function modules resulting in escalation of privileges causing lo…
Document Builder
Mitigation only
HIGH 8.2
CVE-2024-42374
BEx Web Java Runtime Export Web Service does not
sufficiently validate an XML document accepted from an untrusted source. An
attacker can retrieve in…
Bex Web Java Runtime Export Web Service
Mitigation only
MEDIUM 6.5
CVE-2024-42376
SAP Shared Service Framework does not perform necessary
authorization check for an authenticated user, resulting in escalation of
privileges. On succ…
Shared Service Framework
Mitigation only
MEDIUM 5.0
CVE-2024-41737
SAP CRM ABAP (Insights
Management) allows an authenticated attacker to enumerate HTTP endpoints in the
internal network by specially crafting HTTP re…
Crm Abap Insights Management
Mitigation only
MEDIUM 5.4
CVE-2024-41735
SAP Commerce Backoffice does not sufficiently
encode user-controlled inputs, resulting in Cross-Site Scripting (XSS)
vulnerability causing low impact…
Commerce Backoffice
Mitigation only
CRITICAL 9.8
CVE-2024-41730EPSS 76%
In SAP BusinessObjects Business Intelligence
Platform, if Single Signed On is enabled on Enterprise authentication, an
unauthorized user can get a lo…
Business Objects Business Intelligence Platform
Mitigation only
MEDIUM 5.4
CVE-2024-41732
SAP NetWeaver Application Server ABAP allows
an unauthenticated attacker to craft a URL link that could bypass allowlist
controls. Depending on t…
Netweaver Application Server Abap
Mitigation only
MEDIUM 5.3
CVE-2024-41733
In SAP Commerce, valid user accounts can be
identified during the customer registration and login processes. This allows a
potential attacker to lear…
Commerce
Mitigation only
CRITICAL 9.1
CVE-2024-33003
Some OCC API endpoints in SAP Commerce Cloud
allows Personally Identifiable Information (PII) data, such as passwords, email
addresses, mobile number…
Commerce Cloud
Mitigation only
MEDIUM 6.3
CVE-2024-33005
Due to the missing authorization checks in the
local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application
Server (ABAP and Java)…
Netweaver Abap
Mitigation only
MEDIUM 6.5
CVE-2024-37175
SAP CRM WebClient does not
perform necessary authorization check for an authenticated user, resulting in
escalation of privileges. This could allow a…
Customer Relationship Management S4fnd
Mitigation only
MEDIUM 5.4
CVE-2024-37172
SAP S/4HANA Finance (Advanced Payment
Management) does not perform necessary authorization check for an authenticated
user, resulting in escalation o…
S4core
Mitigation only
MEDIUM 5.0
CVE-2024-37171
SAP Transportation Management (Collaboration
Portal) allows an attacker with non-administrative privileges to send a crafted
request from a vulnerabl…
Saptmui
Mitigation only
MEDIUM 5.0
CVE-2024-34689
WebFlow Services of SAP Business Workflow allows
an authenticated attacker to enumerate accessible HTTP endpoints in the
internal network by speciall…
Business Workflow
Mitigation only
HIGH 7.7
CVE-2024-39598
SAP CRM (WebClient UI Framework) allows an
authenticated attacker to enumerate accessible HTTP endpoints in the internal
network by specially craftin…
Customer Relationship Management S4fnd
Mitigation only