Export limit exceeded: 388878 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (388878 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-6377 | 1 Next4biz | 1 Csm (customer Service Management) | 2026-09-08 | 7.5 High |
| Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Path Traversal. This issue affects CSM (Customer Service Management): from 6.8.9 before 8.0.3. | ||||
| CVE-2026-7861 | 1 Next4biz | 1 Csm (customer Service Management) | 2026-09-08 | 9.8 Critical |
| Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (Customer Service Management): through 07092026. NOTE: The vendor is continuing efforts to remediate the vulnerability. | ||||
| CVE-2026-72976 | 1 Microsoft | 10 365 Apps, Microsoft 365, Office 2019 and 7 more | 2026-09-08 | 5 Medium |
| Out-of-bounds read in Microsoft Office Word allows an authorized attacker to disclose information locally. | ||||
| CVE-2026-86469 | 1 Redhat | 5 Enterprise Linux, Hardened Images, Hummingbird and 2 more | 2026-09-08 | 5.3 Medium |
| A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file. | ||||
| CVE-2026-78838 | 1 Appnitro | 1 Machform | 2026-09-08 | N/A |
| A reflected cross-site scripting (XSS) vulnerability in the grid_datasource.php component of AppNitro MachForm v30 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted payload into the filter[filters][0][field] parameter. | ||||
| CVE-2026-78837 | 1 Appnitro | 1 Machform | 2026-09-08 | N/A |
| A SQL injection vulnerability in the ap_form_{id} parameter in AppNitro MachForm v30 allows attackers to access sensitive database information via a crafted SQL statement. | ||||
| CVE-2026-44756 | 1 Sap Se | 1 Sap Extended Passport (epp) Processing | 2026-09-08 | 10 Critical |
| A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application. | ||||
| CVE-2026-44766 | 1 Sap Se | 1 Sap S/4hana (intercompany Matching And Reconciliation) | 2026-09-08 | 6.5 Medium |
| SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed by the database without proper validation. This could allow the user to access sensitive information, resulting in high impact on confidentiality, with no impact on integrity and availability of the application. | ||||
| CVE-2026-58234 | 1 Sap Se | 1 Sap Process Integration (soap Adapter) | 2026-09-08 | 2.2 Low |
| SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nested entity definitions, which under certain conditions could temporarily increase processor load and degrade system responsiveness. Successful exploitation results in low impact on availability with no impact on confidentiality and integrity. | ||||
| CVE-2026-58240 | 1 Sap Se | 1 Sap Netweaver (message Server) | 2026-09-08 | 9.8 Critical |
| SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized actions within the application environment, resulting in a high impact on the confidentiality, integrity, and availability of the affected system. | ||||
| CVE-2026-66768 | 1 Sap Se | 1 Sap Netweaver (sap Gui For Java) | 2026-09-08 | 9 Critical |
| SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. This could allow arbitrary command execution on the victim's machine, leading to a high impact on the confidentiality, integrity, and availability of the affected system. | ||||
| CVE-2026-76958 | 1 Sap Se | 1 Sap Integration Suite | 2026-09-08 | 8.5 High |
| SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML payloads containing malicious external entity declarations. Successful exploitation could allow the attacker to read sensitive file contents from the server and expose them through monitoring or logging output, resulting in a high impact on confidentiality. It could also lead to resource exhaustion, causing a low impact on availability. There is no impact on integrity. | ||||
| CVE-2026-76959 | 1 Sap Se | 1 Sap S/4hana (finance For Advanced Payment Management) | 2026-09-08 | 4.6 Medium |
| SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability. | ||||
| CVE-2026-76960 | 1 Sap Se | 1 Sap S/4hana (finance For Advanced Payment Management) | 2026-09-08 | 3.5 Low |
| SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability. | ||||
| CVE-2026-72973 | 1 Microsoft | 10 365 Apps, Microsoft 365, Office 2019 and 7 more | 2026-09-08 | 8.8 High |
| Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-76961 | 1 Sap Se | 1 Sap S/4hana (finance For Advanced Payment Management) | 2026-09-08 | 3.5 Low |
| SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability. | ||||
| CVE-2026-76962 | 1 Sap Se | 1 Sap S/4hana (manage Bank Chains App) | 2026-09-08 | 4.3 Medium |
| SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send specially crafted requests to delete specific entries that should not be accessible to them. This results in a low impact on availability. There is no impact on confidentiality and integrity. | ||||
| CVE-2026-76968 | 1 Sap | 3 Content Server, Internet Communication Manager, Web Dispatcher | 2026-09-08 | 6.5 Medium |
| SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability. | ||||
| CVE-2026-76969 | 1 Sap Se | 1 Sap Cloud Application Programming Model (cap) | 2026-09-08 | 9.4 Critical |
| @sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credentials and abuse them to replace or delete tenant data. Successful exploitation can result in a high impact on availability and integrity of the application. There may also be partial impact to the confidentiality of business data. | ||||
| CVE-2026-76977 | 1 Sap Se | 1 Sapui5(frame Options Allowlist) | 2026-09-08 | 4.3 Medium |
| SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated attacker could host a malicious page to bypass framing restrictions. If an authenticated victim visits the attacker's page and interacts with it, the attacker could trick the victim into performing unintended actions, resulting in a low impact on integrity. There is no impact on confidentiality and availability. | ||||