Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48891
Total
3931
Critical
14494
High
14248
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-11985 | LOW | 3.6 | On the Zephyr ARM port, enabling the hardware FPU (CONFIG_FPU) forces the "Floating point ABI" choice, which defaults to CONFIG_FP_HARDABI. Both FP_HARDABI and FP_SOFTABI permit … | Aug 11, 2026 |
| CVE-2026-11893 | MEDIUM | 5.9 | The Bluetooth HCI driver for Bouffalo Lab on-chip BLE controllers (BL60x/BL70x/BL61x), bt_bflb_send() in drivers/bluetooth/hci/hci_bflb.c, violates the bt_hci_driver_api.send() buffer-ownership contract. That contract (documented at include/zephyr/drivers/bluetooth.h) requires … | Aug 11, 2026 |
| CVE-2026-8917 | UNKNOWN | — | Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to write a specific value … | Aug 11, 2026 |
| CVE-2026-24330 | MEDIUM | 6.5 | A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an untrusted … | Aug 11, 2026 |
| CVE-2026-24329 | MEDIUM | 4.9 | A flaw was found in wildfly-core. A remote user authenticated as an administrative user can inject a malformed payload into the Inet Address field through … | Aug 11, 2026 |
| CVE-2026-19424 | HIGH | 7.5 | Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a specific parameter to read other users' … | Aug 11, 2026 |
| CVE-2026-66779 | MEDIUM | 6.3 | Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker could generate a malicious link and make it publicly … | Aug 11, 2026 |
| CVE-2026-66778 | MEDIUM | 5.3 | SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker could send a specially crafted request to … | Aug 11, 2026 |
| CVE-2026-66777 | MEDIUM | 5.9 | SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the complexity of the required conditions, an attacker … | Aug 11, 2026 |
| CVE-2026-66776 | MEDIUM | 5.9 | SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially … | Aug 11, 2026 |
| CVE-2026-66775 | MEDIUM | 4.3 | SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthenticated attacker could craft a malicious link and trick … | Aug 11, 2026 |
| CVE-2026-66774 | LOW | 3.7 | SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this under a non-default configuration. Successful exploitation is highly … | Aug 11, 2026 |
| CVE-2026-66773 | MEDIUM | 5.9 | A malicious or compromised OData service could disclose sensitive authentication information and inject untrusted data into the application, which may leads to a high impact … | Aug 11, 2026 |
| CVE-2026-66772 | MEDIUM | 4.3 | SAP BusinessObjects Business Intelligence Platform (Admin Tools) does not perform sufficient authorization check on certain administrative functionality. An attacker authenticated as a non-administrative user could … | Aug 11, 2026 |
| CVE-2026-66771 | MEDIUM | 6.1 | SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted application changes. When another user subsequently opens the adapted … | Aug 11, 2026 |
| CVE-2026-66770 | MEDIUM | 6.3 | Due to an SQL Injection vulnerability in SAP Social intelligence, an authenticated attacker could directly inject an SQL DDL (Data Definition Language) string into the … | Aug 11, 2026 |
| CVE-2026-66764 | MEDIUM | 4.3 | Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated users, allowing them to use rules that have not … | Aug 11, 2026 |
| CVE-2026-66763 | HIGH | 7.9 | SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local … | Aug 11, 2026 |
| CVE-2026-66761 | MEDIUM | 4.3 | SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could send high volumes of data without consuming responses, … | Aug 11, 2026 |
| CVE-2026-66760 | MEDIUM | 6.4 | SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from the same trusted authority … | Aug 11, 2026 |
| CVE-2026-58248 | MEDIUM | 6.5 | SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file containing malicious external references. When the file … | Aug 11, 2026 |
| CVE-2026-58247 | MEDIUM | 5.3 | SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This could disclose limited, non-sensitive data from previously … | Aug 11, 2026 |
| CVE-2026-58245 | LOW | 3.8 | SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of the application to perform authorization check to access … | Aug 11, 2026 |
| CVE-2026-58244 | MEDIUM | 4.3 | SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain application function, allowing a low-privileged authenticated attacker to access information that … | Aug 11, 2026 |
| CVE-2026-58243 | HIGH | 8.8 | SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against … | Aug 11, 2026 |