Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-40135 An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an authenticated attacker… Netweaver Application Server Abap Mitigation only Fix from $1,6002026-05-12 MEDIUM 6.1 CVE-2026-27682 Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages), a… Netweaver Application Server Abap Mitigation only Fix from $1,6002026-05-12 MEDIUM 6.5 CVE-2026-34264 During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user… Human Capital Management Mitigation only Fix from $1,6002026-04-14 MEDIUM 6.1 CVE-2026-34257 Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft malicious URL that, if access… Netweaver Application Server Abap Mitigation only Fix from $1,6002026-04-14 MEDIUM 6.5 CVE-2026-27679 Due to missing authorization checks in the SAP S/4HANA frontend OData Service (Manage Reference Structures), an attacker could update and delete chil… Manage Reference Structures Mitigation only Fix from $1,6002026-04-14 MEDIUM 6.1 CVE-2026-27674 Due to a Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java), an unauthenticated attacker could supply crafted in… Netweaver Application Server Java Mitigation only Fix from $1,6002026-04-14 MEDIUM 5.0 CVE-2026-27688 Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user privileges could read Database… Netweaver Application Server Abap Mitigation only Fix from $1,6002026-03-10 MEDIUM 6.4 CVE-2026-24316 SAP NetWeaver Application Server for ABAP provides an ABAP Report for testing purposes, which allows to send HTTP requests to arbitrary internal or e… Netweaver Application Server Abap Mitigation only Fix from $1,6002026-03-10 MEDIUM 6.4 CVE-2026-24309 Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function modul… Netweaver Application Server Abap Mitigation only Fix from $1,6002026-03-10 MEDIUM 6.1 CVE-2026-24328 SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect th… Business Server Pages Mitigation only Fix from $1,6002026-02-10 HIGH 7.7 CVE-2026-24322 SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allow… Solution Tools Plug In Mitigation only Fix from $1,9502026-02-10 MEDIUM 6.5 CVE-2026-24324 SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to execute a specific query in … Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002026-02-10 MEDIUM 6.1 CVE-2026-24323 The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters that are not sufficiently sa… Document Management System Mitigation only Fix from $1,6002026-02-10 MEDIUM 5.3 CVE-2026-24321 SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these open endpoints to retrieve sens… Commerce Cloud Mitigation only Fix from $1,6002026-02-10 HIGH 8.8 CVE-2026-23687 SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and … Sap Basis Mitigation only Fix from $1,9502026-02-10 HIGH 7.7 CVE-2026-23689 Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network acc… Advanced Planning And Optimization Mitigation only Fix from $1,9502026-02-10 MEDIUM 5.8 CVE-2026-24319 In SAP Business One, sensitive information is written to the application�s memory dump files without obfuscation. Gaining access to this information … Business One Mitigation only Fix from $1,6002026-02-10 MEDIUM 5.2 CVE-2026-24312 An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative user can bypass role restric… Sap Basis Mitigation only Fix from $1,6002026-02-10 CRITICAL 9.6 CVE-2026-0509 SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls with… Netweaver As Abap Kernel Mitigation only Fix from $2,3002026-02-10 HIGH 8.1 CVE-2026-0508 The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert malicious URL within the appli… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502026-02-10 MEDIUM 6.1 CVE-2026-0505 The BSP applications allow an unauthenticated user to manipulate user-controlled URL parameters that are not sufficiently validated. This could resul… Document Management System Mitigation only Fix from $1,6002026-02-10 MEDIUM 5.9 CVE-2026-23684 A race condition vulnerability exists in the SAP Commerce cloud. Because of this when an attacker adds products to a cart, it may result in a cart en… Commerce Cloud Mitigation only Fix from $1,6002026-02-10 CRITICAL 9.9 CVE-2026-0488 An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthoriz… Netweaver Application Server Abap Mitigation only Fix from $2,3002026-02-10 HIGH 7.5 CVE-2026-0485 SAP BusinessObjects BI Platform allows an unauthenticated attacker to send specially crafted requests that could cause the Content Management Server … Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502026-02-10 HIGH 7.5 CVE-2026-0490 SAP BusinessObjects BI Platform allows an unauthenticated attacker to craft a specific network request to the trusted endpoint that breaks the authen… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502026-02-10 MEDIUM 6.5 CVE-2026-0484 Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker could access a specific transa… Sap Basis Mitigation only Fix from $1,6002026-02-10 MEDIUM 6.1 CVE-2026-0514 Due to a Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious link. When an unsusp… Business Connector Mitigation only Fix from $1,6002026-01-13 HIGH 8.1 CVE-2026-0506 Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC functi… Netweaver Application Server Abap Patch available Fix from $1,9502026-01-13 HIGH 8.8 CVE-2026-0500 Due to the usage of vulnerable third party component in SAP Wily Introscope Enterprise Manager (WorkStation), an unauthenticated attacker could creat… Introscope Enterprise Manager Patch available Fix from $1,9502026-01-13 HIGH 7.2 CVE-2026-0498 SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC… S\/4 Hana Patch available Fix from $1,9502026-01-13