6.1

CVSS3.1

CVE-2026-0499 - Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal

SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the server response and executed in a user's browser when the crafted URL is visited, leading to theft of session information, manipulation of portal conโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 1:13 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 7 a.m.

9.1

CVSS3.1

CVE-2026-0498 - Code Injection vulnerability in SAP S/4HANA (Private Cloud and On-Premise)

SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 1:13 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 7 a.m.

4.3

CVSS3.1

CVE-2026-0497 - Missing Authorization check in Business Server Pages Application (Product Designer Web UI)

SAP Product Designer Web UI of Business Server Pages allows authenticated non-administrative users to access non-sensitive information. This results in a low impact on confidentiality, with no impact on integrity or availability of the application.

๐Ÿ“… Published: Jan. 13, 2026, 1:13 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 7 a.m.

6.6

CVSS3.1

CVE-2026-0496 - Multiple vulnerabilities in SAP Fiori App (Intercompany Balance Reconciliation)

SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to upload any file (including script files) without proper file format validation. This has low impact on confidentiality, integrity and availability of the application.

๐Ÿ“… Published: Jan. 13, 2026, 1:13 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4:30 p.m.

5.1

CVSS3.1

CVE-2026-0495 - Multiple vulnerabilities in SAP Fiori App (Intercompany Balance Reconciliation)

SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to send uploaded files to arbitrary emails which could enable effective phishing campaigns. This has low impact on confidentiality, integrity and availability of the application.

๐Ÿ“… Published: Jan. 13, 2026, 1:13 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 7 a.m.

4.3

CVSS3.1

CVE-2026-0494 - Information Disclosure vulnerability in SAP Fiori App (Intercompany Balance Reconciliation)

Under certain conditions SAP Fiori App Intercompany Balance Reconciliation application allows an attacker to access information which would otherwise be restricted. This has low impact on confidentiality of the application, integrity and availability are not impacted.

๐Ÿ“… Published: Jan. 13, 2026, 1:13 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 7 a.m.

4.3

CVSS3.1

CVE-2026-0493 - Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori App (Intercompany Balance Reconciliatiโ€ฆ

Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori App Intercompany Balance Reconciliation an attacker could execute state?changing actions using an inappropriate request type, this deviation from expected request semantics may allow an attacker to trigger unintended actions on bโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 1:13 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 7 a.m.

8.8

CVSS3.1

CVE-2026-0492 - Privilege escalation vulnerability in SAP HANA database

SAP HANA database is vulnerable to privilege escalation allowing an attacker with valid credentials of any user to switch to another user potentially gaining administrative access. This exploit could result in a total compromise of the system๏ฟฝs confidentiality, integrity, and availability.

๐Ÿ“… Published: Jan. 13, 2026, 1:13 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 7 a.m.

9.1

CVSS3.1

CVE-2026-0491 - Code Injection vulnerability in SAP Landscape Transformation

SAP Landscape Transformation allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 1:12 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 7 a.m.

5.5

CVSS3.1

CVE-2025-68784 - xfs: fix a UAF problem in xattr repair

In the Linux kernel, the following vulnerability has been resolved: xfs: fix a UAF problem in xattr repair The xchk_setup_xattr_buf function can allocate a new value buffer, which means that any reference to ab->value before the call could become a dangling pointer. Fix this by moving an assignmโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 2176 of 34,919
ยซ previous page ยป next page
Filters