CVE Vulnerability Database
Search and browse 397,697 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11618 | HIGH | 7.3 | 0.4% | Jun 9, 2026 | A vulnerability was determined in DTStack Taier up to 1.4.0. The affected element is the function preHandle of the file ... |
| CVE-2026-10862 | MEDIUM | 6.4 | 0.2% | Jun 9, 2026 | The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion body field in all ver... |
| CVE-2026-8795 | HIGH | 7.8 | 0.1% | Jun 9, 2026 | A YAML injection vulnerability exists in the Windows.Collectors.Remapping artifact of Rapid7 Velociraptor before version... |
| CVE-2026-44757 | MEDIUM | 4.7 | 0.2% | Jun 9, 2026 | SAP Wily Introscope Enterprise Manager allows an unauthenticated attacker to craft a specially crafted URL. Under certai... |
| CVE-2026-44755 | MEDIUM | 4.3 | 0.1% | Jun 9, 2026 | SAP Business Objects Business Intelligence Platform does not sufficiently validate email sending parameters supplied by ... |
| CVE-2026-44754 | MEDIUM | 6.6 | 0.2% | Jun 9, 2026 | The Remote Function Call (RFC) modules of the Operational Data Provisioning Data Replication API (ODP-RFC) are missing c... |
| CVE-2026-44751 | HIGH | 7.1 | 0.2% | Jun 9, 2026 | Application server ABAP does not perform necessary authorization checks for an authenticated user allowing an attacker t... |
| CVE-2026-44750 | MEDIUM | 4.3 | 0.2% | Jun 9, 2026 | SAP MDG (Review Match Groups Application) does not perform the necessary authorization checks for authenticated users. T... |
| CVE-2026-44748 | CRITICAL | 9.9 | 0.2% | Jun 9, 2026 | SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtai... |
| CVE-2026-44746 | MEDIUM | 6.1 | 0.2% | Jun 9, 2026 | Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver JAVA (JDBC Test Servlet), an unauthenticate... |
| CVE-2026-44744 | MEDIUM | 6.5 | 0.2% | Jun 9, 2026 | SAP S/4HANA(On-Premise) contains SQL injection vulnerability in a remote-enabled function module component that could be... |
| CVE-2026-44743 | LOW | 3.7 | 0.2% | Jun 9, 2026 | Under certain conditions, when an unauthorized attacker accesses a specific endpoint, SAP Business Objects application l... |
| CVE-2026-40128 | CRITICAL | 9 | 0.5% | Jun 9, 2026 | SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon... |
| CVE-2026-27671 | CRITICAL | 9.8 | 0.4% | Jun 9, 2026 | Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP ... |
| CVE-2026-24315 | MEDIUM | 4.2 | 0.2% | Jun 9, 2026 | SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain, ... |
| CVE-2026-11701 | MEDIUM | 5.4 | 0.2% | Jun 9, 2026 | Inappropriate implementation in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform... |
| CVE-2026-11700 | HIGH | 8.3 | 0.2% | Jun 9, 2026 | Use after free in Tracing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the ren... |
| CVE-2026-11699 | HIGH | 8.8 | 0.2% | Jun 9, 2026 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exp... |
| CVE-2026-11698 | HIGH | 8.8 | 0.2% | Jun 9, 2026 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exp... |
| CVE-2026-11697 | CRITICAL | 9.6 | 0.2% | Jun 9, 2026 | Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to p... |
| CVE-2026-11696 | MEDIUM | 5.3 | 0.2% | Jun 9, 2026 | Uninitialized Use in Video in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had comprom... |
| CVE-2026-11695 | MEDIUM | 4.3 | 0.2% | Jun 9, 2026 | Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to leak cro... |
| CVE-2026-11694 | HIGH | 7.5 | 0.2% | Jun 9, 2026 | Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised t... |
| CVE-2026-11693 | HIGH | 8.1 | 0.2% | Jun 9, 2026 | Inappropriate implementation in Plugins in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compr... |
| CVE-2026-11692 | HIGH | 8.3 | 0.2% | Jun 9, 2026 | Use after free in Read Anything in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised t... |
