Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-58248 SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file… No fix yet Fix from $1,6002026-08-11 MEDIUM 5.3 CVE-2026-58247 SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This could disclose limited, non-sensi… No fix yet Fix from $1,6002026-08-11 HIGH 8.8 CVE-2026-58243 SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to exe… No fix yet Fix from $1,9502026-08-11 MEDIUM 5.9 CVE-2026-58238 SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input… No fix yet Fix from $1,6002026-08-11 MEDIUM 5.9 CVE-2026-58237 WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit t… No fix yet Fix from $1,6002026-08-11 MEDIUM 5.5 CVE-2026-58236 SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing security controls on an internal cod… No fix yet Fix from $1,6002026-08-11 MEDIUM 6.3 CVE-2026-58235 SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer libraries that contain known… No fix yet Fix from $1,6002026-08-11 HIGH 7.0 CVE-2026-58230 SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially … No fix yet Fix from $1,9502026-08-11 HIGH 7.3 CVE-2026-44765 Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access… No fix yet Fix from $1,9502026-08-11 HIGH 7.3 CVE-2026-44764 Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted … No fix yet Fix from $1,9502026-08-11 HIGH 7.6 CVE-2026-44763 SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using s… No fix yet Fix from $1,9502026-08-11 CRITICAL 9.1 CVE-2026-44758 SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected fu… No fix yet Fix from $2,3002026-08-11 MEDIUM 5.3 CVE-2026-40130 SAP SAPSPrint Service has memory corruption vulnerabilities in the handling of certain commands. An unauthenticated attacker could send specially cra… No fix yet Fix from $1,6002026-08-11 CRITICAL 9.8 CVE-2026-34265 SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corr… No fix yet Fix from $2,3002026-08-11 HIGH 8.4 CVE-2026-8718 tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), pass… Patch available Fix from $1,9502026-08-10 CRITICAL 9.3 CVE-2026-48161 react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contained malicious commits 7b79148d… No fix yet Fix from $2,3002026-08-10 HIGH 8.6 CVE-2025-30241 Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before passing it to sy… No fix yet Fix from $1,9502026-08-10 MEDIUM 5.1 CVE-2025-30240 The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By placing a crafted symbolic li… No fix yet Fix from $1,6002026-08-10 HIGH 8.5 CVE-2025-30239 In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data may allow an… No fix yet Fix from $1,9502026-08-10 HIGH 8.6 CVE-2025-30238 In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to execute higher-privileged oper… No fix yet Fix from $1,9502026-08-10 HIGH 8.7 CVE-2025-30237 The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not consistently enforced on certa… No fix yet Fix from $1,9502026-08-10 MEDIUM 5.4 CVE-2026-72918 Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.… No fix yet Fix from $1,6002026-08-10 MEDIUM 5.9 CVE-2026-72917 AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.0.0 to 1.15.0, Any… Patch available Fix from $1,6002026-08-10 MEDIUM 6.3 CVE-2026-72916 Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, PrivateAddressCheck.pri… Patch available Fix from $1,6002026-08-10 HIGH 7.5 CVE-2026-72915 Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta.1, any logged-in local user … Patch available Fix from $1,9502026-08-10 HIGH 7.5 CVE-2026-72914 Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, the administrative stat… Patch available Fix from $1,9502026-08-10 MEDIUM 6.5 CVE-2026-73033 Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in the pageIntegritySubmission() method in src/integri… No fix yet Fix from $1,6002026-08-10 HIGH 8.1 CVE-2026-73030 unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize … Patch available Fix from $1,9502026-08-10 HIGH 7.3 CVE-2026-72913 Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/window.py write unauthenticated d… Patch available Fix from $1,9502026-08-10 CRITICAL 9.9 CVE-2026-72911 ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls i… Patch available Fix from $2,3002026-08-10