4.3

CVSS3.1

CVE-2026-0494 - Information Disclosure vulnerability in SAP Fiori App (Intercompany Balance Reconciliation)

Under certain conditions SAP Fiori App Intercompany Balance Reconciliation application allows an attacker to access information which would otherwise be restricted. This has low impact on confidentiality of the application, integrity and availability are not impacted.

📅 Published: Jan. 13, 2026, 1:13 a.m. 🔄 Last Modified: Jan. 13, 2026, 1:13 a.m.

4.3

CVSS3.1

CVE-2026-0493 - Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori App (Intercompany Balance Reconciliati…

Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori App Intercompany Balance Reconciliation an attacker could execute state?changing actions using an inappropriate request type, this deviation from expected request semantics may allow an attacker to trigger unintended actions on b…

📅 Published: Jan. 13, 2026, 1:13 a.m. 🔄 Last Modified: Jan. 13, 2026, 1:13 a.m.

8.8

CVSS3.1

CVE-2026-0492 - Privilege escalation vulnerability in SAP HANA database

SAP HANA database is vulnerable to privilege escalation allowing an attacker with valid credentials of any user to switch to another user potentially gaining administrative access. This exploit could result in a total compromise of the system�s confidentiality, integrity, and availability.

📅 Published: Jan. 13, 2026, 1:13 a.m. 🔄 Last Modified: Jan. 13, 2026, 1:13 a.m.

9.1

CVSS3.1

CVE-2026-0491 - Code Injection vulnerability in SAP Landscape Transformation

SAP Landscape Transformation allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively funct…

📅 Published: Jan. 13, 2026, 1:12 a.m. 🔄 Last Modified: Jan. 13, 2026, 1:12 a.m.

8.7

CVSS4.0

CVE-2024-58340 - LangChain <= 0.3.1 MRKLOutputParser ReDoS

LangChain versions up to and including 0.3.1 contain a regular expression denial-of-service (ReDoS) vulnerability in the MRKLOutputParser.parse() method (libs/langchain/langchain/agents/mrkl/output_parser.py). The parser applies a backtracking-prone regular expression when extracting tool actions f…

📅 Published: Jan. 12, 2026, 11:05 p.m. 🔄 Last Modified: Jan. 12, 2026, 11:05 p.m.

8.4

CVSS4.0

CVE-2024-14021 - LlamaIndex <= 0.11.6 BGEM3Index Unsafe Deserialization

LlamaIndex (run-llama/llama_index) versions up to and including 0.11.6 contain an unsafe deserialization vulnerability in BGEM3Index.load_from_disk() in llama_index/indices/managed/bge_m3/base.py. The function uses pickle.load() to deserialize multi_embed_store.pkl from a user-supplied persist_dir …

📅 Published: Jan. 12, 2026, 11:04 p.m. 🔄 Last Modified: Jan. 12, 2026, 11:04 p.m.

8.7

CVSS4.0

CVE-2024-58339 - LlamaIndex <= 0.12.2 VannaQueryEngine SQL Execution Allows Resource Exhaustion

LlamaIndex (run-llama/llama_index) versions up to and including 0.12.2 contain an uncontrolled resource consumption vulnerability in the VannaPack VannaQueryEngine implementation. The custom_query() logic generates SQL statements from a user-supplied prompt and executes them via vn.run_sql() withou…

📅 Published: Jan. 12, 2026, 11:04 p.m. 🔄 Last Modified: Jan. 12, 2026, 11:04 p.m.

8.7

CVSS4.0

CVE-2025-15514 - Ollama Multi-Modal Model Image Processing NULL Pointer Dereference

Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functionality. When processing base64-encoded image data via the /api/chat endpoint, the application fails to validate that the decoded data represents valid m…

📅 Published: Jan. 12, 2026, 11:03 p.m. 🔄 Last Modified: Jan. 12, 2026, 11:03 p.m.

6.8

CVSS4.0

CVE-2026-22214 - RIOT OS <= 2026.01-devel-317 Stack-Based Buffer Overflow in ethos Serial Frame Parser

RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the ethos utility due to missing bounds checking when processing incoming serial frame data. The vulnerability occurs in the _handle_char() function, where incoming frame bytes are appended…

📅 Published: Jan. 12, 2026, 11:03 p.m. 🔄 Last Modified: Jan. 12, 2026, 11:03 p.m.

2.4

CVSS4.0

CVE-2026-22213 - RIOT OS <= 2026.01-devel-317 Stack-Based Buffer Overflow in tapslip6 Utility

RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the tapslip6 utility. The vulnerability is caused by unsafe string concatenation in the devopen() function, which constructs a device path using unbounded user-controlled input. The utility…

📅 Published: Jan. 12, 2026, 11:03 p.m. 🔄 Last Modified: Jan. 12, 2026, 11:03 p.m.
Total resulsts: 327160
Page 6 of 32,716
« previous page » next page
Filters