Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.4 LOW
CVE-2026-40131 — SQL Injection vulnerability in SAP HANA Deployment Infrastructure (HDI) deploy library

SQL injection vulnerability exists in @sap/hdi-deploy package, where SQL queries are dynamically constructed using user input without proper parameterization or prepared statements. Successful exploi…

| Injection
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
4.3 MEDIUM
CVE-2026-40129 — Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Pl…

Due to a Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform, an authenticated attacker could send specially crafted inputs to the application. If processe…

Remote | Injection
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
9.6 CRITICAL
CVE-2026-34263 — Missing authentication check in SAP Commerce cloud configuration

Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious input injection, resulting in arbitrary server-side code execution, leading to hi…

Remote | Misconfiguration
May 12, 2026 May 15, 2026
May 12, 2026
May 15, 2026
9.6 CRITICAL
CVE-2026-34260 — SQL injection vulnerability in SAP S/4HANA (SAP Enterprise Search for ABAP)

SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to inject malicious SQL statements through user-controlled input. The applica…

Remote | Injection
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
8.2 HIGH
CVE-2026-34259 — OS Command Injection Vulnerability in SAP Forecasting & Replenishment

Due to an OS Command Execution vulnerability in SAP Forecasting & Replenishment, an authenticated attacker with administrative authorizations could abuse a non-remote-enabled function to execute arbi…

| Injection
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
4.7 MEDIUM
CVE-2026-34258 — Content Spoofing vulnerability in SAPUI5 (Search UI)

SAPUI5 (Search UI) allows an unauthenticated attacker to manipulate specific URL parameters on the Search UI to include malicious content. Successful exploitation may mislead victim users into clicki…

sapui5 | Remote | Cross-Site Scripting
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
6.1 MEDIUM
CVE-2026-27682 — Reflected Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server AB…

Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages), an unauthenticated attacker could craft a URL that …

netweaver_application_server_abap | Remote | Cross-Site Scripting
May 12, 2026 Jun 03, 2026
May 12, 2026
Jun 03, 2026
5.4 MEDIUM
CVE-2026-0502 — Cross Site Request Forgery (CSRF) in SAP BusinessObjects Business Intelligence Platform

Due to insufficient CSRF protection in SAP BusinessObjects Business Intelligence Platform ,an authenticated user could be tricked by an attacker to send unintended requests to the web server. This ha…

businessobjects_business_intelligence_platform | Remote | Cross-Site Request Forgery
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
9.8 CRITICAL
CVE-2026-45393 — Local privilege escalation to SYSTEM in Cribl Edge for Windows

A vulnerability chain in Cribl Edge for Windows before 4.17.1 allows a local authenticated user to escalate privileges to NT AUTHORITY\SYSTEM. Incorrect default permissions on the Windows installer's…

Remote
May 12, 2026 Jun 02, 2026
May 12, 2026
Jun 02, 2026
9.8 CRITICAL
CVE-2026-45392 — DOM-based XSS in Cribl Stream

DOM-based cross-site scripting (XSS) in Cribl Stream before 4.17.1 allows a remote attacker to execute arbitrary JavaScript in the browser of an authenticated user who is tricked into visiting a craf…

Remote
May 12, 2026 Jun 02, 2026
May 12, 2026
Jun 02, 2026
9.8 CRITICAL
CVE-2026-45391 — Local privilege escalation in Cribl Edge for Linux

A command injection vulnerability in Cribl Edge for Linux versions 3.2.0 through 4.17.0 allows a local unprivileged user to execute arbitrary commands in the context of the Cribl Edge service account.

Remote
May 12, 2026 Jun 02, 2026
May 12, 2026
Jun 02, 2026
3.2 LOW
CVE-2026-45362 — Sangoma Switchvox SIP Authentication Credential Exposure

Sangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file.

switchvox | Authentication
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
9.6 CRITICAL
CVE-2026-45321 — TanStack Unspecified Vulnerability - [Actively Exploited]

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate …

May 12, 2026 May 29, 2026
May 12, 2026
May 29, 2026
4.3 MEDIUM
CVE-2026-8349 — omec-project amf NGAP Message memory corruption

A flaw has been found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGAP Message Handler. Executing a manipulation can lead to memory corruption. The attac…

amf | Remote | Memory Corruption
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
8.8 HIGH
CVE-2026-8346 — D-Link DIR-816 portForward command injection

A vulnerability was detected in D-Link DIR-816 1.10CNB05_R1B011D88210. This affects the function portForward. Performing a manipulation of the argument ip_address results in command injection. The at…

dir-816_firmware dir-816 | Remote | Injection
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
8.8 HIGH
CVE-2026-8345 — D-Link DIR-816 singlePortForward sub_445E7C command injection

A security vulnerability has been detected in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this issue is the function sub_445E7C of the file /goform/singlePortForward. Such manipulation of the …

dir-816_firmware dir-816 | Remote | Injection
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
9.8 CRITICAL
CVE-2026-43914 — Vaultwarden: Brute-force protection bypass vulnerability

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.4, there is a security vulnerability in Vaultwarden that allows bypassing the login brute-force protection if email 2fa is …

vaultwarden | Remote | Authentication
May 11, 2026 May 13, 2026
May 11, 2026
May 13, 2026
8.1 HIGH
CVE-2026-43913 — Vaultwarden: Unconfirmed Owner Can Purge Entire Organization Vault

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden allows an unconfirmed organization owner to purge the entire organization vault. The organization invite flo…

vaultwarden | Remote | Authorization
May 11, 2026 May 13, 2026
May 11, 2026
May 13, 2026
8.7 HIGH
CVE-2026-43912 — Vaultwarden: Cross-Org Group Binding Enables Unauthorized Read And Write Access Into Anot…

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden does not enforce that a groups_users.users_organizations_uuid entry belongs to the same organization as grou…

vaultwarden | Remote | Authorization
May 11, 2026 May 15, 2026
May 11, 2026
May 15, 2026
8.1 HIGH
CVE-2026-43911 — Vaultwarden: Refresh tokens not invalidated on security stamp rotation

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, refresh tokens are not invalidated when the user's security_stamp is rotated by some security-sensitive operations (pass…

vaultwarden | Remote | Authentication
May 11, 2026 May 18, 2026
May 11, 2026
May 18, 2026
Showing 20 of 7366 Results