Known Vulnerabilities for Sap Web Application Server by Sap
Listed below are 10 of the newest known vulnerabilities associated with "Sap Web Application Server" by "Sap".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-82673 json | Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in ash-project ash_admin allows wr... | Not Provided | 2026-08-31 | 2026-08-31 |
| CVE-2026-82078 json | An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The... | Not Provided | 2026-08-28 | 2026-08-29 |
| CVE-2026-81528 json | A MongoDB C# driver document-replacement code path omits the element-name/shape validation that the equivalent write paths ap... | Not Provided | 2026-08-27 | 2026-08-28 |
| CVE-2026-81526 json | The MongoDB Rust Driver does not neutralize special characters in a caller-supplied target identifier before embedding it in ... | Not Provided | 2026-08-27 | 2026-08-28 |
| CVE-2026-80428 json | ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel endpoint at components/ILIA... | Not Provided | 2026-08-26 | 2026-08-29 |
| CVE-2026-80426 json | FiftyOne renders a dataset field's description as markup. The sidebar field-information component at app/packages/core/src/co... | Not Provided | 2026-08-26 | 2026-08-26 |
| CVE-2026-80348 json | TarsWeb enforces its per-application roles by calling AuthService from individual controller methods, and four methods in app... | Not Provided | 2026-08-26 | 2026-08-26 |
| CVE-2026-80104 json | DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload di... | Not Provided | 2026-08-25 | 2026-08-28 |
| CVE-2026-79773 json | Winter CMS before 1.2.13 contains a local file inclusion vulnerability in the JavascriptImporter filter that allows authentic... | Not Provided | 2026-08-25 | 2026-08-28 |
| CVE-2026-79670 json | Ech0 before 4.4.3 contains a stored cross-site scripting vulnerability in the file upload endpoint that validates Content-Typ... | Not Provided | 2026-08-25 | 2026-08-25 |