Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.4 LOW
CVE-2026-23686 — CRLF Injection vulnerability in SAP NetWeaver Application Server Java

Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administrative access could submit specially crafted content to the application. If proc…

netweaver_application_server_java | Remote | Injection
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
4.4 MEDIUM
CVE-2026-23685 — Insecure Deserialization vulnerability in SAP NetWeaver (JMS service)

Due to a Deserialization vulnerability in SAP NetWeaver (JMS service), an attacker authenticated as an administrator with local access could submit specially crafted content to the server. If process…

netweaver | Denial of Service
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
5.9 MEDIUM
CVE-2026-23684 — Race condition vulnerability in SAP Commerce Cloud

A race condition vulnerability exists in the SAP Commerce cloud. Because of this when an attacker adds products to a cart, it may result in a cart entry being created with erroneous product value whi…

commerce_cloud | Remote | Race Condition
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
4.3 MEDIUM
CVE-2026-23681 — Missing Authorization check in a function module in SAP Support Tools Plug-In

Due to missing authorization check in a function module in SAP Support Tools Plug-In, an authenticated attacker could invoke specific function modules to retrieve information about the system and its…

solution_tools_plug-in | Remote | Authorization
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
9.6 CRITICAL
CVE-2026-0509 — Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls without the required S_RFC authorization in certain ca…

Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
8.1 HIGH
CVE-2026-0508 — Open Redirect vulnerability in SAP BusinessObjects Business Intelligence Platform

The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert malicious URL within the application. Upon successful exploitation, the victim m…

businessobjects_business_intelligence_platform | Remote | Server-Side Request Forgery
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
6.1 MEDIUM
CVE-2026-0505 — Multiple vulnerabilities in BSP Applications of SAP Document Management System

The BSP applications allow an unauthenticated user to manipulate user-controlled URL parameters that are not sufficiently validated. This could result in unvalidated redirection to attacker-controlle…

s4core erp document_management_system | Remote | Authentication
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
7.5 HIGH
CVE-2026-0490 — Denial of service (DOS) in SAP BusinessObjects BI Platform

SAP BusinessObjects BI Platform allows an unauthenticated attacker to craft a specific network request to the trusted endpoint that breaks the authentication, which prevents the legitimate users from…

Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
9.9 CRITICAL
CVE-2026-0488 — Code Injection vulnerability in SAP CRM and SAP S/4HANA (Scripting Editor)

An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ab…

Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
5.0 MEDIUM
CVE-2026-0486 — Missing Authorization Check in ABAP based SAP systems

In ABAP based SAP systems a remote enabled function module does not perform necessary authorization checks for an authenticated user resulting in disclosure of system information.This has low impact …

solution_tools_plug-in | Remote | Authorization
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
7.5 HIGH
CVE-2026-0485 — Denial of service (DOS) vulnerability in SAP BusinessObjects BI Platform

SAP BusinessObjects BI Platform allows an unauthenticated attacker to send specially crafted requests that could cause the Content Management Server (CMS) to crash and automatically restart. By repea…

businessobjects_business_intelligence_platform | Remote | Denial of Service
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
6.5 MEDIUM
CVE-2026-0484 — Missing Authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA

Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker could access a specific transaction code and modify the text data in the system.…

sap_basis | Remote | Authorization
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
5.5 MEDIUM
CVE-2026-2258 — aardappel lobster wfc.h WaveFunctionCollapse memory corruption

A flaw has been found in aardappel lobster up to 2025.4. Affected by this vulnerability is the function WaveFunctionCollapse in the library dev/src/lobster/wfc.h. Executing a manipulation can lead to…

lobster | Memory Corruption
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
7.2 HIGH
CVE-2026-0845 — WCFM - WooCommerce Frontend Manager <= 6.7.24 - Authenticated (Shop Manager+) Arbitrary O…

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege esc…

Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
8.1 HIGH
CVE-2025-15314 — Tanium addressed an arbitrary file deletion vulnerability in end-user-cx.

Tanium addressed an arbitrary file deletion vulnerability in end-user-cx.

Feb 10, 2026 Feb 20, 2026
Feb 10, 2026
Feb 20, 2026
7.1 HIGH
CVE-2025-15313 — Tanium addressed an arbitrary file deletion vulnerability in Tanium EUSS.

Tanium addressed an arbitrary file deletion vulnerability in Tanium EUSS.

endpoint_euss euss | Path Traversal
Feb 10, 2026 Feb 24, 2026
Feb 10, 2026
Feb 24, 2026
7.8 HIGH
CVE-2025-15310 — Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.

Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.

Feb 10, 2026 Feb 24, 2026
Feb 10, 2026
Feb 24, 2026
4.3 MEDIUM
CVE-2025-15147 — WCFM Membership – WooCommerce Memberships for Multivendor Marketplace <= 2.11.8 - Insecur…

The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.8 via the '…

wcfm_membership | Remote | Authorization
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
7.7 HIGH
CVE-2026-25958 — Cube privilege escalation via a specially crafted request

Cube is a semantic layer for building data applications. From 0.27.19 to before 1.5.13, 1.4.2, and 1.0.14, it is possible to make a specially crafted request with a valid API token that leads to priv…

cube.js | Remote | Authorization
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
6.5 MEDIUM
CVE-2026-25957 — Cube Denial of Service (DoS) - An authenticated attacker can crash the server by sending …

Cube is a semantic layer for building data applications. From 1.1.17 to before 1.5.13 and 1.4.2, it is possible to make the entire Cube API unavailable by submitting a specially crafted request to a …

cube.js | Remote | Denial of Service
Feb 09, 2026 Feb 24, 2026
Feb 09, 2026
Feb 24, 2026
Showing 20 of 5087 Results