Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,637
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 11,921 - 11,940 of 36,815 CVEs

SQL injection vulnerability exists in @sap/hdi-deploy package, where SQL queries are dynamically constructed using user input without proper parameterization or prepared statements. Successful exploitation could allow the high privileged users to alter the SELECT statements impacting confidentiality...

Vendor: SAP_SE
Product: SAP HANA Deployment Infrastructure (HDI) deploy library
Published: May 12, 2026
Source: NVD
CVE-2026-40129 MEDIUM - 4.3

Due to a Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform, an authenticated attacker could send specially crafted inputs to the application. If processed by the application, this input could be delivered to users subscribed to the channel and result in ...

Vendor: SAP_SE
Product: SAP Application Server ABAP for SAP NetWeaver and ABAP Platform
Published: May 12, 2026
Source: NVD
CVE-2026-34263 CRITICAL - 9.6

Due to improper Spring Security configuration, SAP Commerce cloud allows an unauthenticated user to perform malicious configuration upload and code injection, resulting in arbitrary server-side code execution, leading to high impact on Confidentiality, Integrity, and Availability of the application.

Vendor: SAP_SE
Product: SAP Commerce cloud configuration
Published: May 12, 2026
Source: NVD
CVE-2026-34260 CRITICAL - 9.6

SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to inject malicious SQL statements through user-controlled input. The application directly concatenates this malicious user input into SQL queries, which are then passed to the u...

Vendor: SAP_SE
Product: SAP S/4HANA (SAP Enterprise Search for ABAP)
Published: May 12, 2026
Source: NVD
CVE-2026-34259 HIGH - 8.2

Due to an OS Command Execution vulnerability in SAP Forecasting & Replenishment, an authenticated attacker with administrative authorizations could abuse a non-remote-enabled function to execute arbitrary operating system commands. Successful exploitation could allow the attacker to read or modi...

Vendor: SAP_SE
Product: SAP Forecasting & Replenishment
Published: May 12, 2026
Source: NVD
CVE-2026-34258 MEDIUM - 4.7

SAPUI5 (Search UI) allows an unauthenticated attacker to manipulate specific URL parameters on the Search UI to include malicious content. Successful exploitation may mislead victim users into clicking and accessing attacker-controlled pages rendered by the application. This vulnerability has a low ...

Vendor: SAP_SE
Product: SAPUI5 (Search UI)
Published: May 12, 2026
Source: NVD
CVE-2026-27682 MEDIUM - 4.7

Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages), an unauthenticated attacker could craft a URL that exploits an unprotected URL parameter to embed a malicious script. If a victim clicks the link, the i...

Vendor: SAP_SE
Product: SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages)
Published: May 12, 2026
Source: NVD
CVE-2026-0502 MEDIUM - 5.4

Due to insufficient CSRF protection in SAP BusinessObjects Business Intelligence Platform ,an authenticated user could be tricked by an attacker to send unintended requests to the web server. This has low impact on integrity and availability of the application. There is no impact on confidentiality ...

Published: May 12, 2026
Source: NVD
CVE-2026-45393 CRITICAL - 9.8

Reserved. Details will be published at disclosure.

Vendor: Cribl
Product: Cribl Edge
Published: May 12, 2026
Source: NVD
CVE-2026-45392 CRITICAL - 9.8

Reserved. Details will be published at disclosure.

Vendor: Cribl
Product: Cribl Stream
Published: May 12, 2026
Source: NVD
CVE-2026-45391 CRITICAL - 9.8

Reserved. Details will be published at disclosure.

Vendor: Cribl
Product: Cribl Edge
Published: May 12, 2026
Source: NVD

Sangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file.

Vendor: Sangoma
Product: Switchvox
Published: May 12, 2026
Source: NVD
CVE-2026-45321 CRITICAL - 9.6

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself wa...

Vendor: npm
Product: @tanstack/arktype-adapter
Published: May 12, 2026
Source: NVD
CVE-2026-8349 MEDIUM - 4.3

A flaw has been found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGAP Message Handler. Executing a manipulation can lead to memory corruption. The attack can be launched remotely. The exploit has been published and may be used. This patch is called 8a4c...

Published: May 12, 2026
Source: NVD
CVE-2026-8346 MEDIUM - 6.3

A vulnerability was detected in D-Link DIR-816 1.10CNB05_R1B011D88210. This affects the function portForward. Performing a manipulation of the argument ip_address results in command injection. The attack can be initiated remotely. The exploit is now public and may be used.

Vendor: dlink
Product: dir-816_firmware
Published: May 12, 2026
Source: NVD
CVE-2026-8345 MEDIUM - 6.3

A security vulnerability has been detected in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this issue is the function sub_445E7C of the file /goform/singlePortForward. Such manipulation of the argument ip_address leads to command injection. It is possible to launch the attack remotely. The exp...

Vendor: dlink
Product: dir-816_firmware
Published: May 11, 2026
Source: NVD
CVE-2026-43914 HIGH - 7.3

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.4, there is a security vulnerability in Vaultwarden that allows bypassing the login brute-force protection if email 2fa is enabled. If email 2fa is enabled, the unprotected 2fa-function send_email_login (email.rs, api endpoi...

Vendor: dani-garcia
Product: vaultwarden
Published: May 11, 2026
Source: NVD
CVE-2026-43913 HIGH - 8.1

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden allows an unconfirmed organization owner to purge the entire organization vault. The organization invite flow uses a two-step process: accepting an invite transitions membership from Invited to Accepted, and a...

Vendor: dani-garcia
Product: vaultwarden
Published: May 11, 2026
Source: NVD
CVE-2026-43912 HIGH - 8.7

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden does not enforce that a groups_users.users_organizations_uuid entry belongs to the same organization as groups.groups_uuid, or a collections_groups.collections_uuid entry belongs to the same organization as co...

Vendor: dani-garcia
Product: vaultwarden
Published: May 11, 2026
Source: NVD
CVE-2026-43911 MEDIUM - 6.8

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, refresh tokens are not invalidated when the user's security_stamp is rotated by some security-sensitive operations (password change, KDF change, key rotation, email change, org admin password reset, emergency access ...

Vendor: dani-garcia
Product: vaultwarden
Published: May 11, 2026
Source: NVD