Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-0492 SAP HANA database is vulnerable to privilege escalation allowing an attacker with valid credentials of any user to switch to another user potentially… Hana Database Patch available Fix from $1,9502026-01-13 MEDIUM 6.8 CVE-2025-42894 Due to a Path Traversal vulnerability in SAP Business Connector, an attacker authenticated as an administrator with adjacent access could read, write… Business Connector Mitigation only Fix from $1,6002025-11-11 MEDIUM 6.1 CVE-2025-42893 Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL that, if accessed by a victi… Business Connector Mitigation only Fix from $1,6002025-11-11 MEDIUM 6.8 CVE-2025-42892 Due to an OS Command Injection vulnerability in SAP Business Connector, an authenticated attacker with administrative access and adjacent network acc… Business Connector Mitigation only Fix from $1,6002025-11-11 MEDIUM 6.1 CVE-2025-42886 Due to a Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could generate a malicious link an… Business Connector Mitigation only Fix from $1,6002025-11-11 MEDIUM 5.3 CVE-2025-42926 SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files within the web appl… Netweaver Application Server Java Patch available Fix from $1,6002025-09-09 MEDIUM 6.1 CVE-2025-42920 Due to a Cross-Site Scripting (XSS) vulnerability in the SAP Supplier Relationship Management, an unauthenticated attacker could generate a malicious… Supplier Relationship Management Patch available Fix from $1,6002025-09-09 MEDIUM 5.4 CVE-2025-42936 The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations for different user roles, this … Sap Basis Patch available Fix from $1,6002025-08-12 MEDIUM 6.1 CVE-2025-42956 SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to create a malicious link which they can make publicly av… Sap Basis Patch available Fix from $1,6002025-07-08 MEDIUM 5.3 CVE-2025-42988 Under certain conditions, SAP Business Objects Business Intelligence Platform allows an unauthenticated attacker to enumerate HTTP endpoints in the i… Businessobjects Business Intelligence Platform Patch available Fix from $1,6002025-06-10 HIGH 7.6 CVE-2025-23192 SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store malicious script within a workspace. W… Businessobjects Business Intelligence Patch available Fix from $1,9502025-06-10 CRITICAL 9.1 CVE-2025-42999 KEVEPSS 12% SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserializ… Netweaver Mitigation only Fix from $2,3002025-05-13 CRITICAL 9.8 CVE-2025-30012 The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component, which allows an unauthenticated attac… Supplier Relationship Management Mitigation only Fix from $2,3002025-05-13 HIGH 7.5 CVE-2025-30018 The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an application servlet request wi… Supplier Relationship Management Mitigation only Fix from $1,9502025-05-13 MEDIUM 6.1 CVE-2025-30009 he Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which … Supplier Relationship Management Mitigation only Fix from $1,6002025-05-13 MEDIUM 6.1 CVE-2025-30010 The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which… Supplier Relationship Management Mitigation only Fix from $1,6002025-05-13 MEDIUM 5.3 CVE-2025-30011 The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which… Supplier Relationship Management Mitigation only Fix from $1,6002025-05-13 CRITICAL 9.8 CVE-2025-31324 KEVEPSS 100% SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially ma… Netweaver Mitigation only Fix from $2,3002025-04-24 HIGH 7.1 CVE-2025-31332 Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker who has local access to the system could modify f… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502025-04-08 MEDIUM 6.1 CVE-2025-25245 SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An… Businessobjects Business Intelligence Platform Patch available Fix from $1,6002025-03-11 HIGH 7.5 CVE-2025-23193 SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respond differently based on the ex… Sap Basis Patch available Fix from $1,9502025-02-11 MEDIUM 6.5 CVE-2025-0064 Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intelligence platform allows an attacker with admin rig… Businessobjects Business Intelligence Platform Patch available Fix from $1,6002025-02-11 CRITICAL 9.1 CVE-2025-0061 SAP BusinessObjects Business Intelligence Platform allows an unauthenticated attacker to perform session hijacking over the network without any user … Businessobjects Business Intelligence Platform Patch available Fix from $2,3002025-01-14 HIGH 8.8 CVE-2025-0063 SAP NetWeaver AS ABAP and ABAP Platform does not check for authorization when a user executes some RFC function modules. This could lead to an attack… Sap Basis Patch available Fix from $1,9502025-01-14 HIGH 8.8 CVE-2025-0066 Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted infor… Sap Basis Patch available Fix from $1,9502025-01-14 MEDIUM 6.5 CVE-2025-0058 In SAP Business Workflow and SAP Flexible Workflow, an authenticated attacker can manipulate a parameter in an otherwise legitimate resource request … Sap Basis Patch available Fix from $1,6002025-01-14 MEDIUM 6.5 CVE-2025-0060 SAP BusinessObjects Business Intelligence Platform allows an authenticated user with restricted access to inject malicious JS code which can read sen… Businessobjects Business Intelligence Platform Patch available Fix from $1,6002025-01-14 MEDIUM 5.3 CVE-2025-0053 SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to gain unauthorized access to system information. By using a specific… Sap Basis Patch available Fix from $1,6002025-01-14 MEDIUM 5.3 CVE-2024-32732 Under certain conditions SAP BusinessObjects Business Intelligence platform allows an attacker to access information which would otherwise be restric… Businessobjects Business Intelligence Platform Patch available Fix from $1,6002024-12-10 HIGH 7.1 CVE-2024-47595 An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access. On successful exploitation t… Host Agent Mitigation only Fix from $1,9502024-11-12