Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-58248 — XML External Entity Injection in SAP BusinessObjects Business Intelligence

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file containing malicious external references. When th…

businessobjects_business_intelligence | Remote | XML External Entity
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
5.3 MEDIUM
CVE-2026-58247 — Memory Corruption vulnerability in SAP ABAP Platform

SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This could disclose limited, non-sensitive data from previously used memory, leading to …

abap_platform | Remote | Information Disclosure
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
3.8 LOW
CVE-2026-58245 — Hard-coded Credentials in SAP Advanced Planning and Optimization (Model Mix Planning)

SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of the application to perform authorization check to access certain functionalities …

advanced_planning_and_optimization | Remote | Authentication
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
4.3 MEDIUM
CVE-2026-58244 — Missing Authorization Check in SAP Manufacturing Integration and Intelligence (MII)

SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain application function, allowing a low-privileged authenticated attacker to access informa…

Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
8.8 HIGH
CVE-2026-58243 — Privilege Escalation vulnerability in SAP ABAP Developer Tools

SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP …

Remote | Authorization
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
4.2 MEDIUM
CVE-2026-58241 — Missing Authorization Check in SAP NetWeaver and ABAP Platform (Change and Transport Syst…

SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard) allows a low-privileged user to modify configuration tables that control access to data objects d…

Remote | Authorization
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
3.7 LOW
CVE-2026-58239 — Multiple vulnerabilities in SAP Business AI Platform (Approuter)

SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send specially crafted requests to spoof the tenant context under conditions not ful…

Remote | Authorization
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
5.9 MEDIUM
CVE-2026-58238 — Multiple vulnerabilities in SAP Business AI Platform (Approuter)

SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input that causes the component to crash and restart. S…

Remote | Denial of Service
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
5.9 MEDIUM
CVE-2026-58237 — Multiple vulnerabilities in SAP Business AI Platform (Approuter)

WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit this to access restricted functionality. Successful…

Remote | Authorization
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
5.5 MEDIUM
CVE-2026-58236 — OS Command Injection vulnerability in Application Server ABAP of SAP NetWeaver and ABAP P…

SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing security controls on an internal code path leading to operating system command executi…

netweaver_application_server_abap | Remote | Injection
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
6.3 MEDIUM
CVE-2026-58235 — Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Document Services)

SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer libraries that contain known vulnerabilities addressed in later versions. A lo…

Remote | Cryptography
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.0 HIGH
CVE-2026-58230 — Multiple vulnerabilities in SAP Business AI Platform (Approuter)

SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential materi…

Remote | Server-Side Request Forgery
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.3 HIGH
CVE-2026-44765 — Missing Authorization Check in SAP Manufacturing Integration and Intelligence

Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access scheduling-related application functions without …

Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.3 HIGH
CVE-2026-44764 — Missing Authorization Check in SAP Manufacturing Integration and Intelligence

Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parame…

Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.6 HIGH
CVE-2026-44763 — Directory Traversal vulnerability in SAP Manufacturing Integration and Intelligence

SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires…

manufacturing_integration_and_intelligence | Remote | Path Traversal
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
3.7 LOW
CVE-2026-44762 — Security Misconfiguration in SAP Data Services Management Console

SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks certain restrictive directives, which could enable an authenticated malicious us…

Remote | Misconfiguration
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
9.1 CRITICAL
CVE-2026-44758 — Code Injection vulnerability in Manufacturing Integration and Intelligence

SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient…

Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
5.3 MEDIUM
CVE-2026-40130 — Memory Corruption vulnerability in SAPSPrint Service

SAP SAPSPrint Service has memory corruption vulnerabilities in the handling of certain commands. An unauthenticated attacker could send specially crafted requests that trigger a buffer overflow in th…

sapsprint | Remote | Memory Corruption
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
9.8 CRITICAL
CVE-2026-34265 — Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Pla…

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially discl…

Remote | Memory Corruption
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
8.4 HIGH
CVE-2026-8718 — Out-of-bounds write in DTLS peer Connection ID getsockopt (`TLS_DTLS_PEER_CID_VALUE`) in …

tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied optval directly to mbedtls_…

zephyr zephyr | Memory Corruption
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
Showing 20 of 10131 Results