|
751
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Due to a missing authorization check in SAP Business Analytics and SAP Content Management, an authenticated user could make unauthorized calls to certain remote function modules, potentially accessin…
|
CWE-862
Missing Authorization
|
CVE-2026-34261
|
2026-04-18 00:18 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
752
|
5.0 |
MEDIUM
Network
|
-
|
-
|
Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2026-34262
|
2026-04-18 00:18 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
753
|
6.5 |
MEDIUM
Network
|
-
|
-
|
During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user with low privileges could guess and enumerate the…
|
CWE-204
Response Discrepancy Information Exposure
|
CVE-2026-34264
|
2026-04-18 00:18 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
754
|
3.7 |
LOW
Network
|
-
|
-
|
A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Simcenter STAR-CCM+ (A…
|
CWE-295
Improper Certificate Validation
|
CVE-2025-40745
|
2026-04-18 00:18 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
755
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3 with UMC). The affected application contains an authentication weakness due to insufficient validation of user identity in th…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-24032
|
2026-04-18 00:18 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
756
|
8.8 |
HIGH
Network
|
-
|
-
|
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3). Affected products do not properly validate user authorization when processing password reset requests. This could allow an …
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-25654
|
2026-04-18 00:18 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
757
|
8.8 |
HIGH
Network
|
-
|
-
|
A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions < V5.8). User Administrators are allowed to administer groups they belong to. This could …
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-27668
|
2026-04-18 00:18 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
758
|
9.3 |
CRITICAL
Local
|
-
|
-
|
Sandbox Escape Vulnerability in Terrarium allows arbitrary code execution with root privileges on a host process via JavaScript prototype chain traversal.
|
-
|
CVE-2026-5752
|
2026-04-18 00:17 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
759
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Reflected Cross-Site Scripting (XSS) Vulnerability in Radware Alteon 34.5.4.0 vADC load-balancer allows an attacker to inject malicious scripts into the website, potentially leading to unauthorized a…
|
-
|
CVE-2026-5754
|
2026-04-18 00:17 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
760
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Configuration File Modification Vulnerability in DRC Central Office Services (COS) allows an attacker to modify the server's configuration file, potentially leading to mass data exfil…
|
-
|
CVE-2026-5756
|
2026-04-18 00:17 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|