A vulnerability described as critical has been identified in SAP Strategic Enterprise Management up to SEM-BW 605. This affects an unknown function of the component Business Server Page. Executing a manipulation can lead to missing authorization.
This vulnerability is registered as CVE-2026-40132. It is possible to launch the attack remotely. No exploit is available.
Applying a patch is advised to resolve this issue.
A vulnerability, which was classified as critical, was found in SAP HANA Deployment Infrastructure deploy library 1.00. Affected by this issue is some unknown functionality of the component SELECT Statement Handler. Such manipulation leads to sql injection.
This vulnerability is traded as CVE-2026-40131. The attack may be launched remotely. There is no exploit available.
It is advisable to implement a patch to correct this issue.
A vulnerability was found in SAP Application Server ABAP for NetWeaver and ABAP Platform and classified as critical. Affected by this vulnerability is an unknown functionality. Such manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2026-40129. The attack can be launched remotely. No exploit exists.
Applying a patch is advised to resolve this issue.
A vulnerability was found in SAP Forecasting & Replenishment 702/712/713/714. It has been declared as critical. This affects an unknown part. Executing a manipulation can lead to command injection.
The identification of this vulnerability is CVE-2026-34259. The attack can only be executed locally. There is no exploit available.
A patch should be applied to remediate this issue.
A vulnerability was found in SAP Commerce Cloud Configuration 2211-JDK21/COM_CLOUD 2211/HY_COM 2205. It has been rated as very critical. This vulnerability affects unknown code. The manipulation leads to incomplete cleanup.
This vulnerability is referenced as CVE-2026-34263. Remote exploitation of the attack is possible. No exploit is available.
To fix this issue, it is recommended to deploy a patch.
A vulnerability marked as critical has been reported in SAP S4HANA AP_BAI 751 up to AP_BAI 758. The impacted element is an unknown function. Performing a manipulation results in sql injection.
This vulnerability is cataloged as CVE-2026-34260. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability labeled as problematic has been found in SAP NetWeaver Application Server ABAP. The affected element is an unknown function of the component Business Server Page. Such manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2026-27682. The attack may be performed from remote. There is no available exploit.
It is best practice to apply a patch to resolve this issue.
A vulnerability, which was classified as problematic, has been found in SAP UI5 up to SAP 1.108. Affected by this vulnerability is an unknown functionality of the component Search UI. This manipulation of the argument URL causes clickjacking.
This vulnerability appears as CVE-2026-34258. The attack may be initiated remotely. There is no available exploit.
To fix this issue, it is recommended to deploy a patch.
A vulnerability was found in vllm-project vllm up to 0.19.x. It has been rated as problematic. This impacts the function extract_hidden_states. Performing a manipulation of the argument repetition_penalty/frequency_penalty/presence_penalty results in incorrect calculation of buffer size.
This vulnerability is known as CVE-2026-44223. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
A vulnerability marked as critical has been reported in 0xJacky nginx-ui up to 2.3.4. Impacted is an unknown function. Performing a manipulation results in server-side request forgery.
This vulnerability was named CVE-2026-44015. The attack may be initiated remotely. There is no available exploit.