CVE-2026-0496
published 2026-01-13CVE-2026-0496: SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to upload any file (including script files) without proper file…
PriorityP336medium6.6CVSS 3.1
AVNACLPRHUINSCCLILAL
EPSS
0.19%
8.9th percentile
SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to upload any file (including script files) without proper file format validation. This has low impact on confidentiality, integrity and availability of the application.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap_se | sap_fiori_app | — | — |
| sap_se | sap_fiori_app | — | — |
| sap_se | sap_fiori_app | — | — |
| sap_se | sap_fiori_app | — | — |
| sap_se | sap_fiori_app | — | — |
| sap_se | sap_fiori_app | — | — |
| sap_se | sap_fiori_app | — | — |
| sap_se | sap_fiori_app | — | — |
| sap_se | sap_fiori_app | — | — |
| sap_se | sap_fiori_app | — | — |
| sap_se | sap_fiori_app | — | — |
| sap_se | sap_fiori_app | — | — |
| sap_se | sap_fiori_app | — | — |
| sap_se | sap_fiori_app | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-47167 neovim: Vim: Arbitrary code execution via crafted step-definition patterns [epel-all]
bugzilla·2026-07-08·CVSS 5.3
CVE-2026-47167 [MEDIUM] CVE-2026-47167 neovim: Vim: Arbitrary code execution via crafted step-definition patterns [epel-all]
CVE-2026-47167 neovim: Vim: Arbitrary code execution via crafted step-definition patterns [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Vim is an open source, command line text editor. Prior to version 9.2.0496, a code injection vulnerability exists in s:stepmatch() in the cucumber filetype plugin (runtime/ftplugin/cucumber.vim) on Vim builds with +ruby support. Step-definition patterns read from .rb files under the repository's features/*/ or stories/*/ directories are embedded into a Ruby Kernel.eval argument without sufficient escaping, allowing a crafted pattern in an attacker-controlled repository
Bugzilla
CVE-2026-47167 neovim: Vim: Arbitrary code execution via crafted step-definition patterns [fedora-all]
bugzilla·2026-07-08·CVSS 5.3
CVE-2026-47167 [MEDIUM] CVE-2026-47167 neovim: Vim: Arbitrary code execution via crafted step-definition patterns [fedora-all]
CVE-2026-47167 neovim: Vim: Arbitrary code execution via crafted step-definition patterns [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Vim is an open source, command line text editor. Prior to version 9.2.0496, a code injection vulnerability exists in s:stepmatch() in the cucumber filetype plugin (runtime/ftplugin/cucumber.vim) on Vim builds with +ruby support. Step-definition patterns read from .rb files under the repository's features/*/ or stories/*/ directories are embedded into a Ruby Kernel.eval argument without sufficient escaping, allowing a crafted pattern in an attacker-controlled reposito
2026-01-13
Published