Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2026-40135
An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an authenticated attacker…
Netweaver Application Server Abap
Mitigation only
MEDIUM 6.1
CVE-2026-27682
Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages), a…
Netweaver Application Server Abap
Mitigation only
MEDIUM 6.5
CVE-2026-34264
During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user…
Human Capital Management
Mitigation only
MEDIUM 6.1
CVE-2026-34257
Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft malicious URL that, if access…
Netweaver Application Server Abap
Mitigation only
MEDIUM 6.5
CVE-2026-27679
Due to missing authorization checks in the SAP S/4HANA frontend OData Service (Manage Reference Structures), an attacker could update and delete chil…
Manage Reference Structures
Mitigation only
MEDIUM 6.1
CVE-2026-27674
Due to a Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java), an unauthenticated attacker could supply crafted in…
Netweaver Application Server Java
Mitigation only
MEDIUM 5.0
CVE-2026-27688
Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user privileges could read Database…
Netweaver Application Server Abap
Mitigation only
MEDIUM 6.4
CVE-2026-24316
SAP NetWeaver Application Server for ABAP provides an ABAP Report for testing purposes, which allows to send HTTP requests to arbitrary internal or e…
Netweaver Application Server Abap
Mitigation only
MEDIUM 6.4
CVE-2026-24309
Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function modul…
Netweaver Application Server Abap
Mitigation only
MEDIUM 6.1
CVE-2026-24328
SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect th…
Business Server Pages
Mitigation only
HIGH 7.7
CVE-2026-24322
SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allow…
Solution Tools Plug In
Mitigation only
MEDIUM 6.5
CVE-2026-24324
SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to execute a specific query in …
Businessobjects Business Intelligence Platform
Mitigation only
MEDIUM 6.1
CVE-2026-24323
The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters that are not sufficiently sa…
Document Management System
Mitigation only
MEDIUM 5.3
CVE-2026-24321
SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these open endpoints to retrieve sens…
Commerce Cloud
Mitigation only
HIGH 8.8
CVE-2026-23687
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and …
Sap Basis
Mitigation only
HIGH 7.7
CVE-2026-23689
Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network acc…
Advanced Planning And Optimization
Mitigation only
MEDIUM 5.8
CVE-2026-24319
In SAP Business One, sensitive information is written to the application�s memory dump files without obfuscation. Gaining access to this information …
Business One
Mitigation only
MEDIUM 5.2
CVE-2026-24312
An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative user can bypass role restric…
Sap Basis
Mitigation only
CRITICAL 9.6
CVE-2026-0509
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls with…
Netweaver As Abap Kernel
Mitigation only
HIGH 8.1
CVE-2026-0508
The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert malicious URL within the appli…
Businessobjects Business Intelligence Platform
Mitigation only
MEDIUM 6.1
CVE-2026-0505
The BSP applications allow an unauthenticated user to manipulate user-controlled URL parameters that are not sufficiently validated. This could resul…
Document Management System
Mitigation only
MEDIUM 5.9
CVE-2026-23684
A race condition vulnerability exists in the SAP Commerce cloud. Because of this when an attacker adds products to a cart, it may result in a cart en…
Commerce Cloud
Mitigation only
CRITICAL 9.9
CVE-2026-0488
An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthoriz…
Netweaver Application Server Abap
Mitigation only
HIGH 7.5
CVE-2026-0485
SAP BusinessObjects BI Platform allows an unauthenticated attacker to send specially crafted requests that could cause the Content Management Server …
Businessobjects Business Intelligence Platform
Mitigation only
HIGH 7.5
CVE-2026-0490
SAP BusinessObjects BI Platform allows an unauthenticated attacker to craft a specific network request to the trusted endpoint that breaks the authen…
Businessobjects Business Intelligence Platform
Mitigation only
MEDIUM 6.5
CVE-2026-0484
Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker could access a specific transa…
Sap Basis
Mitigation only
MEDIUM 6.1
CVE-2026-0514
Due to a Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious link. When an unsusp…
Business Connector
Mitigation only
HIGH 8.1
CVE-2026-0506
Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC functi…
Netweaver Application Server Abap
Patch available
HIGH 8.8
CVE-2026-0500
Due to the usage of vulnerable third party component in SAP Wily Introscope Enterprise Manager (WorkStation), an unauthenticated attacker could creat…
Introscope Enterprise Manager
Patch available
HIGH 7.2
CVE-2026-0498
SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC…
S\/4 Hana
Patch available