Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.1
CVE-2023-6542
Due to lack of proper authorization checks in Emarsys SDK for Android, an attacker can call a particular activity and can forward himself web pages a…
Emarsys Sdk
Mitigation only
MEDIUM 6.4
CVE-2023-49587
SAP Solution Manager - version 720, allows an authorized attacker to execute certain deprecated function modules which can read or modify data of sam…
Solution Manager
Mitigation only
CRITICAL 9.4
CVE-2023-49581
SAP GUI for Windows and SAP GUI for Java allow an unauthenticated attacker to access information which would otherwise be restricted and confidential…
Netweaver Application Server Abap
Mitigation only
HIGH 7.3
CVE-2023-49580
SAP GUI for Windows and SAP GUI for Java - versions SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, allow an unauthenticated attacker to …
Graphical User Interface
Mitigation only
MEDIUM 6.1
CVE-2023-49577
The SAP HCM (SMART PAYE solution) - versions S4HCMCIE 100, SAP_HRCIE 600, SAP_HRCIE 604, SAP_HRCIE 608, does not sufficiently encode user-controlled …
Human Capital Management
Mitigation only
MEDIUM 5.3
CVE-2023-49058
SAP Master Data Governance File Upload application allows an attacker to exploit insufficient validation of path information provided by users, thus …
Master Data Governance
Mitigation only
HIGH 8.1
CVE-2023-42481
In SAP Commerce Cloud - versions HY_COM 1905, HY_COM 2005, HY_COM2105, HY_COM 2011, HY_COM 2205, COM_CLOUD 2211, a locked B2B user can misuse the for…
Commerce Cloud
Mitigation only
HIGH 7.6
CVE-2023-42478
SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to upload agnostic documents in the system which…
Business Objects Business Intelligence Platform
Mitigation only
MEDIUM 6.8
CVE-2023-42476
SAP Business Objects Web Intelligence - version 420, allows an authenticated attacker to inject JavaScript code into Web Intelligence documents whic…
Businessobjects Web Intelligence
Mitigation only
MEDIUM 6.1
CVE-2023-42479
An unauthenticated attacker can embed a hidden access to a Biller Direct URL in a frame which, when loaded by the user, will submit a cross-site scri…
Biller Direct
Mitigation only
HIGH 8.0
CVE-2023-31403
SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB shared folder. As a result, any…
Business One
Mitigation only
MEDIUM 5.3
CVE-2023-41366
Under certain condition SAP NetWeaver Application Server ABAP - versions KERNEL 722, KERNEL 7.53, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54,…
Netweaver Application Server Abap
Mitigation only
MEDIUM 5.3
CVE-2023-42480
The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functionality to identify the legitimat…
Netweaver Application Server Java
Mitigation only
MEDIUM 6.1
CVE-2023-36920
In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-FRAME-OPTIONS response heade…
Enable Now Enable Now Consump Del
Mitigation only
MEDIUM 6.5
CVE-2023-42477
SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a crafted request from a vulnerable web application, ca…
Netweaver Application Server Java
No fix yet
HIGH 7.5
CVE-2023-40310
SAP PowerDesigner Client - version 16.7, does not sufficiently validate BPMN2 XML document imported from an untrusted source. As a result, URLs of ex…
Powerdesigner
Mitigation only
MEDIUM 5.4
CVE-2023-42473
S/4HANA Manage (Withholding Tax Items) - version 106, does not perform necessary authorization checks for an authenticated user, resulting in escalat…
S\/4hana
Mitigation only
MEDIUM 5.4
CVE-2023-42474
SAP BusinessObjects Web Intelligence - version 420, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malici…
Businessobjects Web Intelligence
Mitigation only
MEDIUM 5.4
CVE-2023-40625
S4CORE (Manage Purchase Contracts App) - versions 102, 103, 104, 105, 106, 107, does not perform necessary authorization checks for an authenticated …
S4core
Mitigation only
HIGH 7.1
CVE-2023-40623
SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory under temporary directory and lin…
Businessobjects
Mitigation only
MEDIUM 5.4
CVE-2023-40624
SAP NetWeaver AS ABAP (applications based on Unified Rendering) - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI 758, SAP_BASIS 702,…
Netweaver Application Server Abap
Mitigation only
CRITICAL 9.9
CVE-2023-40622
SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under certain condition allows an authenticated attack…
Businessobjects Business Intelligence
Mitigation only
CRITICAL 9.8
CVE-2023-40309
SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated …
Commoncryptolib
Mitigation only
MEDIUM 6.3
CVE-2023-40621
SAP PowerDesigner Client - version 16.7, allows an unauthenticated attacker to inject VBScript code in a document and have it opened by an unsuspecti…
Powerdesigner
Mitigation only
HIGH 7.3
CVE-2023-42472
Due to insufficient file type validation, SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) - version 420, allows …
Businessobjects Business Intelligence Platform
Mitigation only
HIGH 7.5
CVE-2023-40308
SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a…
Commoncryptolib
Mitigation only
MEDIUM 5.3
CVE-2023-37489
Due to the lack of validation, SAP BusinessObjects Business Intelligence Platform (Version Management System) - version 403, permits an unauthenticat…
Businessobjects Business Intelligence
Mitigation only
MEDIUM 5.3
CVE-2023-41367
Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) - version 7.50, can gain acce…
Netweaver
Mitigation only
MEDIUM 5.3
CVE-2023-41368
The OData service of the S4 HANA (Manage checkbook apps) - versions 102, 103, 104, 105, 106, 107, allows an attacker to change the checkbook name by …
S\/4 Hana
Mitigation only
MEDIUM 6.1
CVE-2023-40306
SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a malicious site due to insufficient UR…
S\/4hana
Mitigation only