Total CVEs

132,176

Critical Severity

2,835

High Severity

10,141

Last 7 Days

1,644
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,681 - 3,700 of 28,581 CVEs
CVE-2026-40137 MEDIUM - 6.1

SAP TAF_APPLAUNCHER within Business Server Pages allows an unauthenticated attacker to craft malicious links that, when clicked by a victim, redirects them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim๏ฟฝs browser. This results in a low impact on co...

Vendor: SAP_SE
Product: Business Server Pages Application (TAF_APPLAUNCHER)
Published: May 12, 2026
Source: NVD
CVE-2026-40136 MEDIUM - 4.3

SAP Financial Consolidation allows an authenticated attacker to disconnect other users by terminating their sessions temporarily preventing access. However, the application itself cannot be compromised resulting in a low impact on availability. There is no impact on confidentiality and integrity of ...

Vendor: SAP_SE
Product: SAP Financial Consolidation
Published: May 12, 2026
Source: NVD
CVE-2026-40135 MEDIUM - 6.5

An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an authenticated attacker with administrative access to execute specially crafted shell commands on the server, bypassing the logging mechanism. This allows the execution of un...

Vendor: SAP_SE
Product: SAP NetWeaver Application Server for ABAP and ABAP Platform
Published: May 12, 2026
Source: NVD
CVE-2026-40134 MEDIUM - 4.3

Due to insufficient authorization checks in the SAP Incentive and Commission Management application, authenticated users could invoke a remote-enabled function module to perform table update operations. This vulnerability has a low impact on integrity with no impact on confidentiality and availabili...

Vendor: SAP_SE
Product: SAP Incentive and Commission Management
Published: May 12, 2026
Source: NVD
CVE-2026-40133 MEDIUM - 6.3

Due to missing authorization check in SAP S/4HANA Condition Maintenance, an authenticated attacker could gain unauthorized access to view and modify condition table records, resulting in low impact on the confidentiality and integrity of the data. Additionally, this vulnerability may prevent the leg...

Vendor: SAP_SE
Product: SAP S/4HANA Condition Maintenance
Published: May 12, 2026
Source: NVD
CVE-2026-40132 MEDIUM - 5.4

Due to missing authorization check in SAP Strategic Enterprise Management (Scorecard Wizard in Business Server Pages), an authenticated attacker could access information that they are otherwise unauthorized to view. This vulnerability also enables the attacker to change the default settings and modi...

Vendor: SAP_SE
Product: SAP Strategic Enterprise Management (BSP application Balanced Scorecard Wizard)
Published: May 12, 2026
Source: NVD

SQL injection vulnerability exists in @sap/hdi-deploy package, where SQL queries are dynamically constructed using user input without proper parameterization or prepared statements. Successful exploitation could allow the high privileged users to alter the SELECT statements impacting confidentiality...

Vendor: SAP_SE
Product: SAP HANA Deployment Infrastructure (HDI) deploy library
Published: May 12, 2026
Source: NVD
CVE-2026-40129 MEDIUM - 4.3

Due to a Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform, an authenticated attacker could send specially crafted inputs to the application. If processed by the application, this input could be delivered to users subscribed to the channel and result in ...

Vendor: SAP_SE
Product: SAP Application Server ABAP for SAP NetWeaver and ABAP Platform
Published: May 12, 2026
Source: NVD
CVE-2026-34263 CRITICAL - 9.6

Due to improper Spring Security configuration, SAP Commerce cloud allows an unauthenticated user to perform malicious configuration upload and code injection, resulting in arbitrary server-side code execution, leading to high impact on Confidentiality, Integrity, and Availability of the application.

Vendor: SAP_SE
Product: SAP Commerce cloud configuration
Published: May 12, 2026
Source: NVD
CVE-2026-34260 CRITICAL - 9.6

SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to inject malicious SQL statements through user-controlled input. The application directly concatenates this malicious user input into SQL queries, which are then passed to the u...

Vendor: SAP_SE
Product: SAP S/4HANA (SAP Enterprise Search for ABAP)
Published: May 12, 2026
Source: NVD
CVE-2026-34259 HIGH - 8.2

Due to an OS Command Execution vulnerability in SAP Forecasting & Replenishment, an authenticated attacker with administrative authorizations could abuse a non-remote-enabled function to execute arbitrary operating system commands. Successful exploitation could allow the attacker to read or modi...

Vendor: SAP_SE
Product: SAP Forecasting & Replenishment
Published: May 12, 2026
Source: NVD
CVE-2026-34258 MEDIUM - 4.7

SAPUI5 (Search UI) allows an unauthenticated attacker to manipulate specific URL parameters on the Search UI to include malicious content. Successful exploitation may mislead victim users into clicking and accessing attacker-controlled pages rendered by the application. This vulnerability has a low ...

Vendor: SAP_SE
Product: SAPUI5 (Search UI)
Published: May 12, 2026
Source: NVD
CVE-2026-27682 MEDIUM - 4.7

Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages), an unauthenticated attacker could craft a URL that exploits an unprotected URL parameter to embed a malicious script. If a victim clicks the link, the i...

Vendor: SAP_SE
Product: SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages)
Published: May 12, 2026
Source: NVD
CVE-2026-0502 MEDIUM - 5.4

Due to insufficient CSRF protection in SAP BusinessObjects Business Intelligence Platform ,an authenticated user could be tricked by an attacker to send unintended requests to the web server. This has low impact on integrity and availability of the application. There is no impact on confidentiality ...

Published: May 12, 2026
Source: NVD
CVE-2026-45393 CRITICAL - 9.8

Reserved. Details will be published at disclosure.

Vendor: Cribl
Product: Cribl Edge
Published: May 12, 2026
Source: NVD
CVE-2026-45392 CRITICAL - 9.8

Reserved. Details will be published at disclosure.

Vendor: Cribl
Product: Cribl Stream
Published: May 12, 2026
Source: NVD
CVE-2026-45391 CRITICAL - 9.8

Reserved. Details will be published at disclosure.

Vendor: Cribl
Product: Cribl Edge
Published: May 12, 2026
Source: NVD

Sangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file.

Vendor: Sangoma
Product: Switchvox
Published: May 12, 2026
Source: NVD
CVE-2026-45321 CRITICAL - 9.6

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself wa...

Vendor: npm
Product: @tanstack/arktype-adapter
Published: May 12, 2026
Source: NVD
CVE-2026-8349 MEDIUM - 4.3

A flaw has been found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGAP Message Handler. Executing a manipulation can lead to memory corruption. The attack can be launched remotely. The exploit has been published and may be used. This patch is called 8a4c...

Published: May 12, 2026
Source: NVD