Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
vulnerability_advisories — Onapsis Security Advisories. https://www.onapsis.com | Kitploit
Tools/GitHubGitHub/onapsis/vulnerability_advisories
Vulnerability AnalysisWeb SecurityThreat IntelligencePapers & ResearchLearning & EducationCurated Resources
GitHubonapsis/vulnerability_advisories

vulnerability_advisories

Onapsis Security Advisories. https://www.onapsis.com

View Repository
10114 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Onapsis Security Advisories

This repository contains Security Advisories for vulnerabilities reported by the Onapsis Research Labs team

Advisories Summary

The following table is a summary of the vulnerabilties described in this repository:

VendorCVECVSSDescriptionLink to Report
SAPCVE-2022-276572.7Directory Traversal vulnerability in SAP Focused Run (Simple Diagnostics Agent 1.0)ONAPSIS-2022-0007.md)
SAPCVE-2022-225475.3Information Disclosure vulnerability in SAP Focused Run (Simple Diagnostics Agent 1.0)ONAPSIS-2022-0006.md)
SAPCVE-2022-261018.2Cross-Site Scripting (XSS) vulnerability in SAP Fiori launchpadONAPSIS-2022-0005_vulnerability_in_SAP_Fiori_launchpad.md)
SAPCVE-2022-243969.3Missing Authentication check in SAP Focused Run (Simple Diagnostics Agent 1.0)ONAPSIS-2022-0004.md)
SAPCVE-2022-243995.4Cross-Site Scripting (XSS) vulnerability in SAP Focused Run (Real User Monitoring)ONAPSIS-2022-0003vulnerability_in_SAP_Focused_Run(Real_User_Monitoring).md)
SAPCVE-2021-336707.5Denial of Service in SAP NetWeaver JAVAONAPSIS-2022-0002
SAPCVE-2021-381628.9HTTP Request Smuggling in SAP Web DispatcherONAPSIS-2022-0001
SAPCVE-2021-375319.9SAP Enterprise Portal - XSLT injectionONAPSIS-2021-0026
SAPCVE-2021-381777.5Null Pointer Dereference vulnerability in SAP CommonCryptoLibONAPSIS-2021-0025
SAPCVE-2021-337076.1SAP Enterprise Portal - Anonymous Stored Open RedirectONAPSIS-2021-0024
SAPCVE-2021-337058.1SAP Enterprise Portal - SSRF iviewCatcherEditorONAPSIS-2021-0023
SAPCVE-2021-337038.3SAP Enterprise Portal - XSS RunContentCreationONAPSIS-2021-0022
SAPCVE-2021-337028.3SAP Enterprise Portal - XSS NavigationReporterONAPSIS-2021-0021
SAPCVE-2021-336874.5SAP Enterprise Portal - Exposed sensitive data in html bodyONAPSIS-2021-0020
SAPCVE-2021-27620
CVE-2021-27622
CVE-2021-27624
CVE-2021-27625
CVE-2021-27626
CVE-2021-27627
5.9Memory Corruption vulnerability in SAP NetWeaver ABAP IGS serviceONAPSIS-2021-0019
SAPCVE-2021-27597
CVE-2021-27633
CVE-2021-27634
7.5Memory Corruption vulnerability in SAP NetWeaver ABAP Gateway serviceONAPSIS-2021-0018
SAPCVE-2021-27606
CVE-2021-27629
CVE-2021-27630
CVE-2021-27631
CVE-2021-27632
7.5Memory Corruption vulnerability in SAP NetWeaver ABAP Enqueue serviceONAPSIS-2021-0017
SAPCVE-2021-276358.7XXE in SAP JAVA NetWeaver System ConnectionsONAPSIS-2021-0016
SAPCVE-2021-27607
CVE-2021-27628
7.5Memory Corruption vulnerability in SAP NetWeaver ABAP Dispatcher serviceONAPSIS-2021-0015
SAPCVE-2020-62079.9Missing authorization check in SAP Solution Manager LM-SERVICE Component SP 11 PL 2ONAPSIS-2021-0014
SAPCVE-2020-2682910.0Missing Authentication Check In SAP NetWeaver AS JAVA P2P Cluster CommunicationONAPSIS-2021-0013
SAPCVE-2021-214809.9SAP MII lack of server side validations leads to RCEONAPSIS-2021-0012
SAPCVE-2020-268307.6Missing authorization check in SolMan End-User Experience MonitoringONAPSIS-2021-0011
SAPCVE-2020-268378.5File exfiltration and DoS in SolMan End-User Experience MonitoringONAPSIS-2021-0010
SAPCVE-2020-63697.5Hard-coded Credentials in CA Introscope Enterprise ManagerONAPSIS-2021-0009
SAPCVE-2020-636410.0OS Command Injection in CA Introscope Enterprise ManagerONAPSIS-2021-0008
SAPCVE-2020-268097.5SAP Hybris eCommerce Exposure of Sensitive Information to an Unauthorized ActorONAPSIS-2021-0007
SAPCVE-2020-268115.3SAP Hybris eCommerce SSRF in acceleratorservices moduleONAPSIS-2021-0006
SAPCVE-2020-268363.4SAP Solution Manager Open Redirect from Trace AnalysisONAPSIS-2021-0005
SAPCVE-2020-268209.1SAP Java OS Remote Code ExecutionONAPSIS-2021-0004
SAPCVE-2020-628710.0SAP RECON SAP JAVA Unauthenticated execution of configuration tasksONAPSIS-2021-0003
SAPCVE-2020-62347.2SAP Multiple root LPE through SAP Host ControlONAPSIS-2021-0002
SAPCVE-2020-620710.0Unauthenticated RCE in SAP SMD Agents through SAP SolManONAPSIS-2021-0001

Vendors Recognition page

  • SAP
Download Tool