Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.7 LOW
CVE-2026-58239 — Multiple vulnerabilities in SAP Business AI Platform (Approuter)

SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send specially crafted requests to spoof the tenant context under conditions not ful…

Remote | Authorization
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
5.9 MEDIUM
CVE-2026-58238 — Multiple vulnerabilities in SAP Business AI Platform (Approuter)

SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input that causes the component to crash and restart. S…

Remote | Denial of Service
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
5.9 MEDIUM
CVE-2026-58237 — Multiple vulnerabilities in SAP Business AI Platform (Approuter)

WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit this to access restricted functionality. Successful…

Remote | Authorization
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
5.5 MEDIUM
CVE-2026-58236 — OS Command Injection vulnerability in Application Server ABAP of SAP NetWeaver and ABAP P…

SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing security controls on an internal code path leading to operating system command executi…

Remote | Injection
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
6.3 MEDIUM
CVE-2026-58235 — Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Document Services)

SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer libraries that contain known vulnerabilities addressed in later versions. A lo…

Remote | Cryptography
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.0 HIGH
CVE-2026-58230 — Multiple vulnerabilities in SAP Business AI Platform (Approuter)

SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential materi…

Remote | Server-Side Request Forgery
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.3 HIGH
CVE-2026-44765 — Missing Authorization Check in SAP Manufacturing Integration and Intelligence

Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access scheduling-related application functions without …

Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.3 HIGH
CVE-2026-44764 — Missing Authorization Check in SAP Manufacturing Integration and Intelligence

Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parame…

Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.6 HIGH
CVE-2026-44763 — Directory Traversal vulnerability in SAP Manufacturing Integration and Intelligence

SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires…

manufacturing_integration_and_intelligence | Remote | Path Traversal
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
3.7 LOW
CVE-2026-44762 — Security Misconfiguration in SAP Data Services Management Console

SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks certain restrictive directives, which could enable an authenticated malicious us…

Remote | Misconfiguration
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
9.1 CRITICAL
CVE-2026-44758 — Code Injection vulnerability in Manufacturing Integration and Intelligence

SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient…

Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
5.3 MEDIUM
CVE-2026-40130 — Memory Corruption vulnerability in SAPSPrint Service

SAP SAPSPrint Service has memory corruption vulnerabilities in the handling of certain commands. An unauthenticated attacker could send specially crafted requests that trigger a buffer overflow in th…

sapsprint | Remote | Memory Corruption
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
9.8 CRITICAL
CVE-2026-34265 — Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Pla…

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially discl…

Remote | Memory Corruption
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
8.4 HIGH
CVE-2026-8718 — Out-of-bounds write in DTLS peer Connection ID getsockopt (`TLS_DTLS_PEER_CID_VALUE`) in …

tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied optval directly to mbedtls_…

zephyr zephyr | Memory Corruption
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
9.3 CRITICAL
CVE-2026-48161 — react18-use was vulnerable to malicious code execution via compromised commits

react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contained malicious commits 7b79148d1495a2505f9277da295a98cf176f4496 through 7b79148d1…

Remote | Supply Chain
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
2.5 LOW
CVE-2026-11812 — UpdateHub: race condition on shared context causes out-of-bounds write and DoS

The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) drives every update operation through a single file-scope ctx structure that holds the CoAP block context, payload buffer, statu…

zephyr zephyr | Race Condition
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
3.7 LOW
CVE-2026-11811 — Socket file-descriptor leak in UpdateHub OTA client start_coap_client() leading to resour…

The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c leaks the CoAP/DTLS socket descriptor on its connection-setup failure paths. The shared error: clea…

zephyr zephyr | Remote | Denial of Service
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
8.6 HIGH
CVE-2025-30241 — OS Command Injection in Web Interface in Multiple TP-Link Aginet Devices

Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before passing it to system-level command execution functions.  An authen…

vx800v | Injection
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
5.1 MEDIUM
CVE-2025-30240 — Arbitrary File Read via Improper Symlink Handling in USB HTTPS Access Path in multiple TP…

The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By placing a crafted symbolic link on supported storage media, an attacker may cau…

vx800v | Path Traversal
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
8.5 HIGH
CVE-2025-30239 — Sensitive Data Exposure due to Hardcoded Cryptographic Keys in Multiple TP-Link Aginet De…

In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data may allow an attacker who has access to device storage to reco…

vx800v | Cryptography
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
Showing 20 of 10121 Results