Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2025-42886 Due to a Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could generate a malicious link an… Business Connector Mitigation only Fix from $1,6002025-11-11 CRITICAL 9.1 CVE-2025-42999 KEVEPSS 12% SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserializ… Netweaver Mitigation only Fix from $2,3002025-05-13 CRITICAL 9.8 CVE-2025-30012 The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component, which allows an unauthenticated attac… Supplier Relationship Management Mitigation only Fix from $2,3002025-05-13 HIGH 7.5 CVE-2025-30018 The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an application servlet request wi… Supplier Relationship Management Mitigation only Fix from $1,9502025-05-13 MEDIUM 6.1 CVE-2025-30009 he Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which … Supplier Relationship Management Mitigation only Fix from $1,6002025-05-13 MEDIUM 6.1 CVE-2025-30010 The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which… Supplier Relationship Management Mitigation only Fix from $1,6002025-05-13 MEDIUM 5.3 CVE-2025-30011 The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which… Supplier Relationship Management Mitigation only Fix from $1,6002025-05-13 CRITICAL 9.8 CVE-2025-31324 KEVEPSS 100% SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially ma… Netweaver Mitigation only Fix from $2,3002025-04-24 HIGH 7.1 CVE-2025-31332 Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker who has local access to the system could modify f… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502025-04-08 HIGH 7.1 CVE-2024-47595 An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access. On successful exploitation t… Host Agent Mitigation only Fix from $1,9502024-11-12 MEDIUM 5.4 CVE-2024-47594 SAP NetWeaver Enterprise Portal (KMC) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability in KMC ser… Netweaver Enterprise Portal Mitigation only Fix from $1,6002024-10-08 MEDIUM 5.4 CVE-2024-45278 SAP Commerce Backoffice does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful … Commerce Backoffice Mitigation only Fix from $1,6002024-10-08 MEDIUM 5.3 CVE-2024-45282 Fields which are in 'read only' state in Bank Statement Draft in Manage Bank Statements application, could be modified by MERGE method. The property … S\/4 Hana Mitigation only Fix from $1,6002024-10-08 MEDIUM 6.5 CVE-2024-37179 SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting… Businessobjects Business Intelligence Mitigation only Fix from $1,6002024-10-08 MEDIUM 5.4 CVE-2024-42373 SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of… Student Life Cycle Management Mitigation only Fix from $1,6002024-08-13 MEDIUM 5.3 CVE-2024-39591 SAP Document Builder does not perform necessary authorization checks for one of the function modules resulting in escalation of privileges causing lo… Document Builder Mitigation only Fix from $1,6002024-08-13 HIGH 8.2 CVE-2024-42374 BEx Web Java Runtime Export Web Service does not sufficiently validate an XML document accepted from an untrusted source. An attacker can retrieve in… Bex Web Java Runtime Export Web Service Mitigation only Fix from $1,9502024-08-13 MEDIUM 6.5 CVE-2024-42376 SAP Shared Service Framework does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. On succ… Shared Service Framework Mitigation only Fix from $1,6002024-08-13 MEDIUM 5.0 CVE-2024-41737 SAP CRM ABAP (Insights Management) allows an authenticated attacker to enumerate HTTP endpoints in the internal network by specially crafting HTTP re… Crm Abap Insights Management Mitigation only Fix from $1,6002024-08-13 MEDIUM 5.4 CVE-2024-41735 SAP Commerce Backoffice does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability causing low impact… Commerce Backoffice Mitigation only Fix from $1,6002024-08-13 CRITICAL 9.8 CVE-2024-41730EPSS 76% In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a lo… Business Objects Business Intelligence Platform Mitigation only Fix from $2,3002024-08-13 MEDIUM 5.4 CVE-2024-41732 SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft a URL link that could bypass allowlist controls. Depending on t… Netweaver Application Server Abap Mitigation only Fix from $1,6002024-08-13 MEDIUM 5.3 CVE-2024-41733 In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to lear… Commerce Mitigation only Fix from $1,6002024-08-13 CRITICAL 9.1 CVE-2024-33003 Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, email addresses, mobile number… Commerce Cloud Mitigation only Fix from $2,3002024-08-13 MEDIUM 6.3 CVE-2024-33005 Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java)… Netweaver Abap Mitigation only Fix from $1,6002024-08-13 MEDIUM 6.5 CVE-2024-37175 SAP CRM WebClient does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow a… Customer Relationship Management S4fnd Mitigation only Fix from $1,6002024-07-09 MEDIUM 5.4 CVE-2024-37172 SAP S/4HANA Finance (Advanced Payment Management) does not perform necessary authorization check for an authenticated user, resulting in escalation o… S4core Mitigation only Fix from $1,6002024-07-09 MEDIUM 5.0 CVE-2024-37171 SAP Transportation Management (Collaboration Portal) allows an attacker with non-administrative privileges to send a crafted request from a vulnerabl… Saptmui Mitigation only Fix from $1,6002024-07-09 MEDIUM 5.0 CVE-2024-34689 WebFlow Services of SAP Business Workflow allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by speciall… Business Workflow Mitigation only Fix from $1,6002024-07-09 HIGH 7.7 CVE-2024-39598 SAP CRM (WebClient UI Framework) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially craftin… Customer Relationship Management S4fnd Mitigation only Fix from $1,9502024-07-09