CVE Vulnerability Database
Search and browse 375,948 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-66761 | MEDIUM | 4.3 | 0.2% | Aug 11, 2026 | SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could s... |
| CVE-2026-66760 | MEDIUM | 6.4 | 0.1% | Aug 11, 2026 | SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges... |
| CVE-2026-58248 | MEDIUM | 6.5 | 0.3% | Aug 11, 2026 | SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a speci... |
| CVE-2026-58247 | MEDIUM | 5.3 | 0.2% | Aug 11, 2026 | SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This coul... |
| CVE-2026-58245 | LOW | 3.8 | 0.2% | Aug 11, 2026 | SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of th... |
| CVE-2026-58244 | MEDIUM | 4.3 | 0.2% | Aug 11, 2026 | SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain applicati... |
| CVE-2026-58243 | HIGH | 8.8 | 0.3% | Aug 11, 2026 | SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attack... |
| CVE-2026-58241 | MEDIUM | 4.2 | 0.2% | Aug 11, 2026 | SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard) allows a low-privi... |
| CVE-2026-58239 | LOW | 3.7 | 0.2% | Aug 11, 2026 | SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send ... |
| CVE-2026-58238 | MEDIUM | 5.9 | 0.3% | Aug 11, 2026 | SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could... |
| CVE-2026-58237 | MEDIUM | 5.9 | 0.2% | Aug 11, 2026 | WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with l... |
| CVE-2026-58236 | MEDIUM | 5.5 | 0.4% | Aug 11, 2026 | SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing securit... |
| CVE-2026-58235 | MEDIUM | 6.3 | 0.2% | Aug 11, 2026 | SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer... |
| CVE-2026-58230 | HIGH | 7 | 0.2% | Aug 11, 2026 | SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated att... |
| CVE-2026-44765 | HIGH | 7.3 | 0.3% | Aug 11, 2026 | Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated... |
| CVE-2026-44764 | HIGH | 7.3 | 0.2% | Aug 11, 2026 | Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated... |
| CVE-2026-44763 | HIGH | 7.6 | 0.3% | Aug 11, 2026 | SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation... |
| CVE-2026-44762 | LOW | 3.7 | 0.1% | Aug 11, 2026 | SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks c... |
| CVE-2026-44758 | CRITICAL | 9.1 | 0.5% | Aug 11, 2026 | SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted... |
| CVE-2026-40130 | MEDIUM | 5.3 | 0.4% | Aug 11, 2026 | SAP SAPSPrint Service has memory corruption vulnerabilities in the handling of certain commands. An unauthenticated atta... |
| CVE-2026-34265 | CRITICAL | 9.8 | 0.4% | Aug 11, 2026 | SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol pars... |
| CVE-2026-8718 | HIGH | 8.4 | 0.1% | Aug 10, 2026 | tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, T... |
| CVE-2026-48161 | CRITICAL | 9.3 | 0.4% | Aug 10, 2026 | react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contain... |
| CVE-2026-11812 | LOW | 2.5 | 0.1% | Aug 10, 2026 | The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) drives every update operation through a single fi... |
| CVE-2026-11811 | LOW | 3.7 | 0.3% | Aug 10, 2026 | The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c leaks the CoAP/DTLS ... |
