Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-24327 — Missing Authorization Check in SAP Strategic Enterprise Management (Balanced Scorecard in…

Due to missing authorization check in SAP Strategic Enterprise Management (Balanced Scorecard in Business Server Pages), an authenticated attacker could access information that they are otherwise una…

strategic_enterprise_management | Remote | Authorization
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
4.3 MEDIUM
CVE-2026-24326 — Missing authorization check in SAP S/4HANA Defense & Security (Disconnected Operations)

Due to a missing authorization check in the Disconnected Operations of the SAP S/4HANA Defense & Security, an attacker with user privileges could call remote-enabled function modules to do direct upd…

s\/4hana_defense_\&_security | Remote | Authorization
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
4.8 MEDIUM
CVE-2026-24325 — Cross Site Scripting (XSS) vulnerability in SAP BusinessObjects Enterprise (Central Manag…

SAP BusinessObjects Enterprise does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an admin user to inject malicious JavaScri…

businessobjects_enterprise | Remote | Cross-Site Scripting
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
6.5 MEDIUM
CVE-2026-24324 — Denial of service (DOS) vulnerability in SAP BusinessObjects Business Intelligence Platfo…

SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to execute a specific query in AdminTools that could cause the Content Management…

businessobjects_business_intelligence_platform | Remote | Denial of Service
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
6.1 MEDIUM
CVE-2026-24323 — Multiple vulnerabilities in BSP Applications of SAP Document Management System

The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters that are not sufficiently sanitized. When a victim accesses a crafted URL, the…

s4core erp document_management_system | Remote | Cross-Site Scripting
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
7.7 HIGH
CVE-2026-24322 — Missing Authorization check in SAP Solution Tools Plug-In (ST-PI)

SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allowing sensitive information to be disclosed. This vu…

solution_tools_plug-in | Remote | Authorization
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
5.3 MEDIUM
CVE-2026-24321 — Information Disclosure vulnerability in SAP Commerce Cloud

SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these open endpoints to retrieve sensitive information that is not intended to be publi…

commerce_cloud | Remote | Information Disclosure
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
3.1 LOW
CVE-2026-24320 — Memory Corruption vulnerability in SAP NetWeaver and ABAP Platform (Application Server AB…

Due to improper memory management in SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker could exploit logical errors in memory management by supplying specially craf…

Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
5.8 MEDIUM
CVE-2026-24319 — Information Disclosure Vulnerability in SAP Business One (B1 Client Memory Dump Files)

In SAP Business One, sensitive information is written to the application�s memory dump files without obfuscation. Gaining access to this information could potentially lead to unauthorized operations …

business_one | Information Disclosure
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
5.2 MEDIUM
CVE-2026-24312 — Missing authorization check in SAP Business Workflow

An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative user can bypass role restrictions by leveraging permissions from a less sensit…

sap_basis | Remote | Authorization
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
7.7 HIGH
CVE-2026-23689 — Denial of service (DOS) in SAP Supply Chain Management

Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedly invoke a remote-enabled functio…

Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
4.3 MEDIUM
CVE-2026-23688 — Missing Authorization check in SAP Fiori App (Manage Service Entry Sheets - Lean Services)

SAP Fiori App Manage Service Entry Sheets does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has low impact on integrity, confident…

s4core | Remote | Authorization
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
8.8 HIGH
CVE-2026-23687 — XML Signature Wrapping in SAP NetWeaver AS ABAP and ABAP Platform

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier…

netweaver_application_server_abap sap_basis | Remote | Authentication
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
3.4 LOW
CVE-2026-23686 — CRLF Injection vulnerability in SAP NetWeaver Application Server Java

Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administrative access could submit specially crafted content to the application. If proc…

netweaver_application_server_java | Remote | Injection
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
4.4 MEDIUM
CVE-2026-23685 — Insecure Deserialization vulnerability in SAP NetWeaver (JMS service)

Due to a Deserialization vulnerability in SAP NetWeaver (JMS service), an attacker authenticated as an administrator with local access could submit specially crafted content to the server. If process…

netweaver | Denial of Service
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
5.9 MEDIUM
CVE-2026-23684 — Race condition vulnerability in SAP Commerce Cloud

A race condition vulnerability exists in the SAP Commerce cloud. Because of this when an attacker adds products to a cart, it may result in a cart entry being created with erroneous product value whi…

commerce_cloud | Remote | Race Condition
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
4.3 MEDIUM
CVE-2026-23681 — Missing Authorization check in a function module in SAP Support Tools Plug-In

Due to missing authorization check in a function module in SAP Support Tools Plug-In, an authenticated attacker could invoke specific function modules to retrieve information about the system and its…

solution_tools_plug-in | Remote | Authorization
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
9.6 CRITICAL
CVE-2026-0509 — Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls without the required S_RFC authorization in certain ca…

Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
8.1 HIGH
CVE-2026-0508 — Open Redirect vulnerability in SAP BusinessObjects Business Intelligence Platform

The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert malicious URL within the application. Upon successful exploitation, the victim m…

businessobjects_business_intelligence_platform | Remote | Server-Side Request Forgery
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
6.1 MEDIUM
CVE-2026-0505 — Multiple vulnerabilities in BSP Applications of SAP Document Management System

The BSP applications allow an unauthenticated user to manipulate user-controlled URL parameters that are not sufficiently validated. This could result in unvalidated redirection to attacker-controlle…

s4core erp document_management_system | Remote | Authentication
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
Showing 20 of 5091 Results