CVE Vulnerability Database

Search and browse 398,037 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-40136MEDIUM4.3SAP Financial Consolidation allows an authenticated attacker to disconnect other users by terminating their sessions tem...
CVE-2026-40135MEDIUM6.5An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that all...
CVE-2026-40134MEDIUM4.3Due to insufficient authorization checks in the SAP Incentive and Commission Management application, authenticated users...
CVE-2026-40133MEDIUM6.3Due to missing authorization check in SAP S/4HANA Condition Maintenance, an authenticated attacker could gain unauthoriz...
CVE-2026-40132MEDIUM5.4Due to missing authorization check in SAP Strategic Enterprise Management (Scorecard Wizard in Business Server Pages), a...
CVE-2026-40131LOW3.4SQL injection vulnerability exists in @sap/hdi-deploy package, where SQL queries are dynamically constructed using user ...
CVE-2026-40129MEDIUM4.3Due to a Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform, an authenticat...
CVE-2026-34263CRITICAL9.6Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious in...
CVE-2026-34260CRITICAL9.6SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacke...
CVE-2026-34259HIGH8.2Due to an OS Command Execution vulnerability in SAP Forecasting & Replenishment, an authenticated attacker with administ...
CVE-2026-34258MEDIUM4.7SAPUI5 (Search UI) allows an unauthenticated attacker to manipulate specific URL parameters on the Search UI to include ...
CVE-2026-27682MEDIUM6.1Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based...
CVE-2026-0502MEDIUM5.4Due to insufficient CSRF protection in SAP BusinessObjects Business Intelligence Platform ,an authenticated user could b...
CVE-2026-45393HIGH8.5A vulnerability chain in Cribl Edge for Windows before 4.17.1 allows a local authenticated user to escalate privileges t...
CVE-2026-45392HIGH8.7DOM-based cross-site scripting (XSS) in Cribl Stream before 4.17.1 allows a remote attacker to execute arbitrary JavaScr...
CVE-2026-45391HIGH8.5A command injection vulnerability in Cribl Edge for Linux versions 3.2.0 through 4.17.0 allows a local unprivileged user...
CVE-2026-45362LOW3.2Sangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file.
CVE-2026-45321CRITICAL9.6On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were publ...
CVE-2026-8349MEDIUM4.3A flaw has been found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGAP Mes...
CVE-2026-8346HIGH8.8A vulnerability was detected in D-Link DIR-816 1.10CNB05_R1B011D88210. This affects the function portForward. Performing...
CVE-2026-8345HIGH8.8A security vulnerability has been detected in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this issue is the funct...
CVE-2026-43914CRITICAL9.8Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.4, there is a security vulnerability in Vaul...
CVE-2026-43913HIGH8.1Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden allows an unconfirmed organiz...
CVE-2026-43912HIGH8.7Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden does not enforce that a group...
CVE-2026-43911HIGH8.1Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, refresh tokens are not invalidated when t...