CVE Vulnerability Database

Search and browse 397,697 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-11618HIGH7.3A vulnerability was determined in DTStack Taier up to 1.4.0. The affected element is the function preHandle of the file ...
CVE-2026-10862MEDIUM6.4The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion body field in all ver...
CVE-2026-8795HIGH7.8A YAML injection vulnerability exists in the Windows.Collectors.Remapping artifact of Rapid7 Velociraptor before version...
CVE-2026-44757MEDIUM4.7SAP Wily Introscope Enterprise Manager allows an unauthenticated attacker to craft a specially crafted URL. Under certai...
CVE-2026-44755MEDIUM4.3SAP Business Objects Business Intelligence Platform does not sufficiently validate email sending parameters supplied by ...
CVE-2026-44754MEDIUM6.6The Remote Function Call (RFC) modules of the Operational Data Provisioning Data Replication API (ODP-RFC) are missing c...
CVE-2026-44751HIGH7.1Application server ABAP does not perform necessary authorization checks for an authenticated user allowing an attacker t...
CVE-2026-44750MEDIUM4.3SAP MDG (Review Match Groups Application) does not perform the necessary authorization checks for authenticated users. T...
CVE-2026-44748CRITICAL9.9SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtai...
CVE-2026-44746MEDIUM6.1Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver JAVA (JDBC Test Servlet), an unauthenticate...
CVE-2026-44744MEDIUM6.5SAP S/4HANA(On-Premise) contains SQL injection vulnerability in a remote-enabled function module component that could be...
CVE-2026-44743LOW3.7Under certain conditions, when an unauthorized attacker accesses a specific endpoint, SAP Business Objects application l...
CVE-2026-40128CRITICAL9SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon...
CVE-2026-27671CRITICAL9.8Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP ...
CVE-2026-24315MEDIUM4.2SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain, ...
CVE-2026-11701MEDIUM5.4Inappropriate implementation in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform...
CVE-2026-11700HIGH8.3Use after free in Tracing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the ren...
CVE-2026-11699HIGH8.8Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exp...
CVE-2026-11698HIGH8.8Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exp...
CVE-2026-11697CRITICAL9.6Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to p...
CVE-2026-11696MEDIUM5.3Uninitialized Use in Video in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had comprom...
CVE-2026-11695MEDIUM4.3Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to leak cro...
CVE-2026-11694HIGH7.5Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised t...
CVE-2026-11693HIGH8.1Inappropriate implementation in Plugins in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compr...
CVE-2026-11692HIGH8.3Use after free in Read Anything in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised t...