Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.9 MEDIUM
CVE-2026-27686 — Missing Authorization check in SAP Business Warehouse (Service API)

Due to a Missing Authorization Check in SAP Business Warehouse (Service API), an authenticated attacker could perform unauthorized actions via an affected RFC function module. Successful exploitation…

Remote | Authorization
Mar 10, 2026 Mar 10, 2026
Mar 10, 2026
Mar 10, 2026
9.1 CRITICAL
CVE-2026-27685 — Insecure Deserialization in SAP NetWeaver Enterprise Portal Administration

SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content that, upon deserialization, could result in a high impact on the confidentiali…

Remote | Misconfiguration
Mar 10, 2026 Mar 10, 2026
Mar 10, 2026
Mar 10, 2026
6.4 MEDIUM
CVE-2026-27684 — SQL Injection Vulnerability in SAP NetWeaver (Feedback Notification)

SAP NetWeaver Feedback Notifications Service contains a SQL injection vulnerability that allows an authenticated attacker to inject arbitrary SQL code through user-controlled input fields. The applic…

Remote | Injection
Mar 10, 2026 Mar 10, 2026
Mar 10, 2026
Mar 10, 2026
5.0 MEDIUM
CVE-2026-24317 — DLL Hijacking vulnerability in SAP GUI for Windows with active GuiXT

SAP GUI for Windows allows DLL files to be loaded from arbitrary directories within the application. An unauthenticated attacker could exploit this vulnerability by persuading a victim to place a mal…

Remote | Misconfiguration
Mar 10, 2026 Mar 10, 2026
Mar 10, 2026
Mar 10, 2026
6.4 MEDIUM
CVE-2026-24316 — Server-Side Request Forgery (SSRF) in SAP NetWeaver Application Server for ABAP

SAP NetWeaver Application Server for ABAP provides an ABAP Report for testing purposes, which allows to send HTTP requests to arbitrary internal or external endpoints. The report is therefore vulnera…

Remote | Server-Side Request Forgery
Mar 10, 2026 Mar 10, 2026
Mar 10, 2026
Mar 10, 2026
5.0 MEDIUM
CVE-2026-24313 — Missing Authorization check in SAP Solution Tools Plug-In (ST-PI)

SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allowing system information to be disclosed. This vulne…

Remote | Authorization
Mar 10, 2026 Mar 10, 2026
Mar 10, 2026
Mar 10, 2026
5.6 MEDIUM
CVE-2026-24311 — Insecure Storage Protection vulnerability in SAP Customer Checkout 2.0

The SAP Customer Checkout application exhibits certain design characteristics that involve locally storing operational data using reversible protection mechanisms. Access to this data, combined with …

| Authentication
Mar 10, 2026 Mar 10, 2026
Mar 10, 2026
Mar 10, 2026
3.5 LOW
CVE-2026-24310 — Missing Authorization check in SAP NetWeaver Application Server for ABAP

Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module and read the sensitive information from database…

Remote | Authorization
Mar 10, 2026 Mar 10, 2026
Mar 10, 2026
Mar 10, 2026
6.4 MEDIUM
CVE-2026-24309 — Missing Authorization check in SAP NetWeaver Application Server for ABAP

Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module to read, modify or insert entries into the datab…

Remote | Authorization
Mar 10, 2026 Mar 10, 2026
Mar 10, 2026
Mar 10, 2026
6.1 MEDIUM
CVE-2026-0489 — DOM-based Cross-Site Scripting (XSS) Vulnerability in SAP Business One (Job Service)

Due to insufficient validation of user-controlled input in the URLs query parameter. SAP Business One Job Service could allow an unauthenticated attacker to inject specially crafted input which upon …

Remote | Cross-Site Scripting
Mar 10, 2026 Mar 10, 2026
Mar 10, 2026
Mar 10, 2026
0.0 NA
CVE-2026-30927 — Admidio: Event participation IDOR - non-leaders can register other users for events via u…

Admidio is an open-source user management solution. Prior to 5.0.6, in modules/events/events_function.php, the event participation logic allows any user who can participate in an event to register OT…

admidio | Authorization
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2026-30925 — Parse Server affected by Regular Expression Denial of Service (ReDoS) via `$regex` query …

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.0-alpha.14 and 8.6.11, a malicious client can subscribe to a LiveQuery with a craf…

parse-server | Denial of Service
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
9.9 CRITICAL
CVE-2026-30921 — OneUptime Synthetic Monitor RCE via exposed Playwright browser object

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.20, OneUptime Synthetic Monitors allow low-privileged project users to submit custom Playwright code that is execute…

oneuptime | Remote | Injection
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
8.6 HIGH
CVE-2026-30920 — OneUptime has broken access control in GitHub App installation flow that allows unauthori…

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback trusts attacker-controlled state and installation_id values and updates Project.…

oneuptime | Remote | Authorization
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
7.6 HIGH
CVE-2026-30919 — facileManager Affected by Stored Cross-Site Scripting (XSS)

facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , stored XSS (also known as persistent or second-order XSS) occurs when an application receives data from …

facilemanager | Remote | Cross-Site Scripting
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
7.6 HIGH
CVE-2026-30918 — facileManager Affected by Reflected Cross-Site Scripting (XSS)

facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , a reflected XSS occurs when an application receives data from an untrusted source and uses it in its HTT…

facilemanager | Remote | Cross-Site Scripting
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2026-30917 — Stored XSS on Bucket namespace pages

Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to 2.1.1, a stored XSS can be inserted into any Bucket table field that has a PAGE type, which will execute wh…

| Cross-Site Scripting
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2026-30916 — Shescape has possible misidentification of shell due to link chains

Shescape is a simple shell escape library for JavaScript. Prior to 2.1.9, an attacker may be able to bypass escaping for the shell being used. This can result, for example, in exposure of sensitive i…

shescape | Information Disclosure
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
4.6 MEDIUM
CVE-2026-30913 — flarum/nickname: Display name injection in notification emails (autolink & markdown)

Flarum is open-source forum software. When the flarum/nicknames extension is enabled, a registered user can set their nickname to a string that email clients interpret as a hyperlink. The nickname is…

Remote | Cross-Site Scripting
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
9.9 CRITICAL
CVE-2026-30887 — OneUptime Affected by Unsandboxed Code Execution in Probe Allows Any Project Member to Ac…

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.18, OneUptime allows project members to run custom Playwright/JavaScript code via Synthetic Monitors to test website…

oneuptime | Remote | Injection
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
Showing 20 of 5066 Results