Unauthenticated SAP Flaw Earns Maximum CVSS Score
SAP ships urgent patches for Commerce Cloud and other critical flaws rated up to 10.0.
30 results for “critical vulnerability”
SAP ships urgent patches for Commerce Cloud and other critical flaws rated up to 10.0.
SAP's August 2026 patch batch addresses 28 flaws, including a 10/10 severity bug in Commerce Cloud that could allow attackers to bypass authentication and execute code.
A critical vulnerability in the MSI Radix AXE6600 router allows remote attackers to gain root access via the wps.cgi interface.
Dell has issued an urgent update for its Virtual Storage Integrator to fix a critical vulnerability that allows unauthenticated attackers to hijack sessions.
A critical vulnerability in CodeIgniter 4 allows attackers to bypass file validation, potentially leading to remote code execution on affected servers.
A critical vulnerability in Azure Logic Apps allows unauthorized information disclosure, earning a CVSS score of 9.6.
A critical remote command injection vulnerability in GL.iNet GL-MT3000 routers allows unauthenticated attackers to execute arbitrary code on affected devices.
A critical vulnerability in Adobe Campaign Classic allows low-privileged attackers to execute arbitrary code without requiring user interaction.
A critical vulnerability in SiYuan software allows unauthorized database manipulation via the searchDocs API endpoint.
A critical vulnerability in the Single Sign On For TNG WordPress plugin allows unauthenticated attackers to reset any user password and take over sites.
A critical vulnerability in Juggle 1.6.0 allows unauthenticated attackers to execute arbitrary OS commands via the H2 database console.
A critical vulnerability in the Flyto-Core verification service allows unauthenticated attackers to steal internal secrets and perform SSRF attacks.
A critical vulnerability in the vault-secrets-webhook allows unauthorized outbound requests and potential theft of cluster-wide service account tokens.
A critical vulnerability in Rich Source's DMS+ allows unauthenticated remote attackers to gain full control over affected devices using a fixed API key.
A critical vulnerability in Azure Cosmos DB allows unauthorized remote code execution, earning a maximum CVSS score of 10.
A critical vulnerability in IBM HMC systems allows unauthenticated attackers to execute arbitrary commands with elevated privileges.
A critical vulnerability in the Ruflo platform allows unauthenticated remote access to enterprise AI agent infrastructure.
A critical vulnerability allows unauthenticated attackers to execute arbitrary commands as root, earning a maximum CVSS score of 9.8.
A critical vulnerability in ModbusServer allows unauthenticated remote attackers to inject malicious input, threatening system integrity and availability.
A critical vulnerability in prebid-server allows attackers to manipulate outbound requests, risking unauthorized data exposure.
A critical vulnerability in IBM Aspera Faspex 5 allows remote authenticated attackers to execute arbitrary code via unquoted shell interpolation.
A critical vulnerability in the PROCON-WEB SCADA GetGridData endpoint allows unauthenticated attackers to execute arbitrary SQL commands.
A critical vulnerability in Apache Thrift c_glib bindings allows for potential memory exposure and system instability, requiring an immediate update.
A critical vulnerability in SiYuan desktop allows attackers to achieve remote code execution through a malicious deep link, necessitating an immediate update.
A critical vulnerability in Anthropic's Claude Cowork allows AI agents to escape their Linux virtual environment and access host macOS data.
A critical vulnerability in the @better-auth/scim plugin allows authenticated users to hijack accounts via provider ID collisions and bypass security controls.
A critical vulnerability in Bing's image processing reveals the risks of treating image conversion tools as simple infrastructure.
A critical vulnerability in Check Point's management software allows attackers to bypass authentication and control network policy.
A critical vulnerability in Auth.js and NextAuth allows attackers to intercept magic-link sign-in flows by exploiting improper Unicode normalization.
A critical vulnerability in the Alibaba Fastjson library allows unauthorized code execution in specific Spring Boot configurations.