|
2561
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Due to insufficient authorization checks in the SAP Incentive and Commission Management application, authenticated users could invoke a remote-enabled function module to perform table update operatio…
|
CWE-862
Missing Authorization
|
CVE-2026-40134
|
2026-05-12 23:19 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2562
|
6.5 |
MEDIUM
Network
|
-
|
-
|
An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an authenticated attacker with administrative access to execute specially c…
|
CWE-77
Command Injection
|
CVE-2026-40135
|
2026-05-12 23:19 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2563
|
4.3 |
MEDIUM
Network
|
-
|
-
|
SAP Financial Consolidation allows an authenticated attacker to disconnect other users by terminating their sessions temporarily preventing access. However, the application itself cannot be compromis…
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2026-40136
|
2026-05-12 23:19 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2564
|
6.1 |
MEDIUM
Network
|
-
|
-
|
SAP TAF_APPLAUNCHER within Business Server Pages allows an unauthenticated attacker to craft malicious links that, when clicked by a victim, redirects them to attacker?controlled sites, potentially e…
|
CWE-79
Cross-site Scripting
|
CVE-2026-40137
|
2026-05-12 23:19 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2565
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions >= V7.80 < V11.0), SIPROTEC 5 6…
|
CWE-334
Small Space of Random Values
|
CVE-2024-54017
|
2026-05-12 23:19 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2566
|
7.5 |
HIGH
Network
|
-
|
-
|
The affected devices contain a null pointer dereference vulnerability while processing specially crafted IPv4 requests. This could allow an attacker to cause denial of service condition. A manual res…
|
CWE-476
NULL Pointer Dereference
|
CVE-2025-40833
|
2026-05-12 23:19 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2567
|
9.1 |
CRITICAL
Network
|
-
|
-
|
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly restrict unauthenticated connections and is susceptible to resource exhaustion…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-22924
|
2026-05-12 23:19 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2568
|
7.5 |
HIGH
Network
|
-
|
-
|
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application is susceptible to resource exhaustion when subjected to high volume of TCP SYN packets
This cou…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-22925
|
2026-05-12 23:19 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2569
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters page of the web interface.
This could allow an authenticated attacker who is author…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25786
|
2026-05-12 23:19 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2570
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagnostics" page of the web interface. This could allow an authenticated attacker w…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25787
|
2026-05-12 23:19 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|