CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2025-5906

    Last Modified: 13 Jun 2025

    A vulnerability classified as critical has been found in code-projects Laundry System 1.0. This affects an unknown part of the file /data/. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 10 Jun 2025
    5.3
    Medium

    CVE-2025-42998

    Last Modified: 15 Apr 2026

    The security settings in the SAP Business One Integration Framework are not adequately checked, allowing attackers to bypass the 403 Forbidden error and access restricted pages. This leads to low impact on confidentiality of the application, there is no impact on integrity and availability.

    Published: 10 Jun 2025
    5.6
    Medium

    CVE-2025-42996

    Last Modified: 15 Apr 2026

    SAP MDM Server allows an attacker to gain control of existing client sessions and execute certain functions without having to re-authenticate giving the ability to access or modify non-sensitive information or consume sufficient resources which could degrade the performance of the server causing low impact on confidentiality, integrity and availibility of the application.

    Published: 10 Jun 2025
    7.5
    High

    CVE-2025-42995

    Last Modified: 15 Apr 2026

    SAP MDM Server Read function allows an attacker to send specially crafted packets which could trigger a memory read access violation in the server process that would then fail and exit unexpectedly causing high impact on availability with no impact on confidentiality and integrity of the application.

    Published: 10 Jun 2025
    7.5
    High

    CVE-2025-42994

    Last Modified: 15 Apr 2026

    SAP MDM Server ReadString function allows an attacker to send specially crafted packets which could trigger a memory read access violation in the server process that would then fail and exit unexpectedly causing high impact on availability with no impact on confidentiality and integrity of the application.

    Published: 10 Jun 2025
    6.7
    Medium

    CVE-2025-42993

    Last Modified: 15 Apr 2026

    Due to a missing authorization check vulnerability in SAP S/4HANA (Enterprise Event Enablement), an attacker with access to the Inbound Binding Configuration could create an RFC destination and assign an arbitrary high-privilege user. This allows the attacker to consume events via the RFC destination, leading to code execution under the privileges of the assigned high-privilege user. While the vulnerability has a low impact on Availability, it significantly poses a high risk to both Confidentiality and Integrity.

    Published: 10 Jun 2025
    4.3
    Medium

    CVE-2025-42991

    Last Modified: 15 Apr 2026

    SAP S/4HANA (Bank Account Application) does not perform necessary authorization checks. This allows an authenticated 'approver' user to delete attachment from bank account application of other user, leading to a low impact on integrity, with no impact on the confidentiality of the data or the availability of the application.

    Published: 10 Jun 2025
    3
    Low

    CVE-2025-42990

    Last Modified: 15 Apr 2026

    Unprotected SAPUI5 applications allow an attacker with basic privileges to inject malicious HTML code into a webpage, with the goal of redirecting users to the attacker controlled URL. This issue could impact the integrity of the application. Confidentiality or Availability are not impacted.

    Published: 10 Jun 2025
    9.6
    Critical

    CVE-2025-42989

    Last Modified: 15 Apr 2026

    RFC inbound processing�does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation the attacker could critically impact both integrity and availability of the application.

    Published: 10 Jun 2025
    3.7
    Low

    CVE-2025-42988

    Last Modified: 23 Oct 2025

    Under certain conditions, SAP Business Objects Business Intelligence Platform allows an unauthenticated attacker to enumerate HTTP endpoints in the internal network by specially crafting HTTP requests. This disclosure of information could further enable the researcher to cause SSRF. It has no impact on integrity and availability of the application.

    Published: 10 Jun 2025
    4.3
    Medium

    CVE-2025-42987

    Last Modified: 15 Apr 2026

    SAP Manage Processing Rules (For Bank Statement) allows an attacker with basic privileges to edit shared rules of any user by tampering the request parameter. Due to missing authorization check, the attacker can edit rules that should be restricted, compromising the integrity of the application.

    Published: 10 Jun 2025
    5.4
    Medium

    CVE-2025-42984

    Last Modified: 15 Apr 2026

    SAP S/4HANA Manage Central Purchase Contract does not perform necessary authorization checks for an authenticated user. Due to this, an attacker could execute the function import on the entity making it inaccessible for unrestricted user. This has low impact on confidentiality and availability of the application.

    Published: 10 Jun 2025
    8.5
    High

    CVE-2025-42983

    Last Modified: 15 Apr 2026

    SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to drop arbitrary SAP database tables, potentially resulting in a loss of data or rendering the system unusable. On successful exploitation, an attacker can completely delete database entries but is not able to read any data.

    Published: 10 Jun 2025
    8.8
    High

    CVE-2025-42982

    Last Modified: 15 Apr 2026

    SAP GRC allows a non-administrative user to access and initiate transaction which could allow them to modify or control the transmitted system credentials. This causes high impact on confidentiality, integrity and availability of the application.

    Published: 10 Jun 2025
    7.6
    High

    CVE-2025-42977

    Last Modified: 15 Apr 2026

    SAP NetWeaver Visual Composer contains a Directory Traversal vulnerability caused by insufficient validation of input paths provided by a high-privileged user. This allows an attacker to read or modify arbitrary files, resulting in a high impact on confidentiality and a low impact on integrity.

    Published: 10 Jun 2025
    5.8
    Medium

    CVE-2025-31325

    Last Modified: 15 Apr 2026

    Due to a Cross-Site Scripting vulnerability in SAP NetWeaver (ABAP Keyword Documentation), an unauthenticated attacker could inject malicious JavaScript into a web page through an unprotected parameter. When a victim accesses the affected page, the script executes in their browser, providing the attacker limited access to restricted information. The vulnerability does not affect data integrity or availability and operates entirely within the context of the client's browser.

    Published: 10 Jun 2025
    8.2
    High

    CVE-2025-23192

    Last Modified: 23 Oct 2025

    SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store malicious script within a workspace. When the victim accesses the workspace, the script will execute in their browser enabling the attacker to potentially access sensitive session information, modify or make browser information unavailable. This leads to a high impact on confidentiality and low impact on integrity, availability.

    Published: 10 Jun 2025
    7.4
    High

    CVE-2025-5905

    Last Modified: 24 Jun 2025

    A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been rated as critical. Affected by this issue is the function setWiFiRepeaterCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument Password leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 10 Jun 2025
    7.4
    High

    CVE-2025-5904

    Last Modified: 24 Jun 2025

    A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. Affected by this vulnerability is the function setWiFiMeshName of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument device_name leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 10 Jun 2025
    9.1
    Critical

    CVE-2025-49794

    Last Modified: 18 Sept 2026

    A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors.

    Published: 10 Jun 2025
    5.4
    Medium

    CVE-2025-44043

    Last Modified: 15 Apr 2026

    Keyoti SearchUnit prior to 9.0.0. is vulnerable to Server-Side Request Forgery (SSRF) in /Keyoti_SearchEngine_Web_Common/SearchService.svc/GetResults and /Keyoti_SearchEngine_Web_Common/SearchService.svc/GetLocationAndContentCategories. An attacker can specify their own SMB server as the indexDirectory value when making POST requests to the affected components. In doing so an attacker can get the SearchUnit server to read and write configuration and log files from/to the attackers server.

    Published: 10 Jun 2025
    7.2
    High

    CVE-2025-46612

    Last Modified: 16 Oct 2025

    The Panel Designer dashboard in Airleader Master and Easy before 6.36 allows remote attackers to execute arbitrary commands via a wizard/workspace.jsp unrestricted file upload. To exploit this, the attacker must login to the administrator console (default credentials are weak and easily guessable) and upload a JSP file via the Panel Designer dashboard.

    Published: 10 Jun 2025
    7.5
    High

    CVE-2025-44044

    Last Modified: 15 Apr 2026

    Keyoti SearchUnit prior to 9.0.0. is vulnerable to XML External Entity (XXE). An attacker who can force a vulnerable SearchUnit host into parsing maliciously crafted XML and/or DTD files can exfiltrate some files from the underlying operating system.

    Published: 10 Jun 2025
    7.5
    High

    CVE-2025-30399

    Last Modified: 20 Feb 2026

    Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.

    Published: 10 Jun 2025
    9.8
    Critical

    CVE-2024-57190

    Last Modified: 24 Jun 2025

    Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP header that contains any user, allowing them to talk to any GraphQL endpoint.

    Published: 10 Jun 2025
    5.4
    Medium

    CVE-2024-57186

    Last Modified: 23 Jun 2025

    In Erxes <1.6.2, an unauthenticated attacker can read arbitrary files from the system using a Path Traversal vulnerability in the /read-file endpoint handler.

    Published: 10 Jun 2025
    6.1
    Medium

    CVE-2024-41505

    Last Modified: 1 Oct 2025

    Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) in the "Pessoas" (persons) section via the field "Profisso" (professor).

    Published: 10 Jun 2025
    6.1
    Medium

    CVE-2024-41504

    Last Modified: 1 Oct 2025

    Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS). In the "Oportunidades" (opportunities) section of the application when creating or editing an "Atividade" (activity), the form field "Descrico" allows injection of JavaScript.

    Published: 10 Jun 2025
    5.4
    Medium

    CVE-2024-57189

    Last Modified: 24 Jun 2025

    In Erxes <1.6.2, an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerability in the importHistoriesCreate GraphQL mutation handler.

    Published: 10 Jun 2025
    5.4
    Medium

    CVE-2024-37395

    Last Modified: 24 Jun 2025

    A stored cross-site scripting (XSS) vulnerability in the Public Survey function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Survey Title' and 'Survey Instructions' fields. This vulnerability could be exploited by attackers to execute malicious scripts when the survey is accessed through its public link. It is advised to update to version 14.2.1 or later to fix this issue.

    Published: 10 Jun 2025
    6.5
    Medium

    CVE-2025-5986

    Last Modified: 20 Apr 2026

    A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abused to fill the disk with garbage data (e.g. using /dev/urandom on Linux) or to leak Windows credentials via SMB links when the email is viewed in HTML mode. While user interaction is required to download the .pdf file, visual obfuscation can conceal the download trigger. Viewing the email in HTML mode is enough to load external content. This vulnerability was fixed in Thunderbird 128.11.1 and Thunderbird 139.0.2.

    Published: 10 Jun 2025
    6.1
    Medium

    CVE-2024-41503

    Last Modified: 1 Oct 2025

    Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) in the field "Ttulo" (title) inside the filter Save option in the "Busca" (search) function.

    Published: 10 Jun 2025
    5.4
    Medium

    CVE-2024-37394

    Last Modified: 24 Jun 2025

    A stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Dashboard title' and 'Dashboard content' text boxes. This can lead to the execution of malicious scripts when the dashboard is viewed. Users are recommended to update to version 14.2.1 or later to mitigate this vulnerability.

    Published: 10 Jun 2025
    5.4
    Medium

    CVE-2024-37396

    Last Modified: 24 Jun 2025

    A stored cross-site scripting (XSS) vulnerability in the Calendar function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Notes' field of a calendar event. This could lead to the execution of malicious scripts when the event is viewed. Updating to version 14.2.1 or later is recommended to remediate this vulnerability.

    Published: 10 Jun 2025
    6.1
    Medium

    CVE-2024-41502

    Last Modified: 1 Oct 2025

    Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) via the form field "Observaces" (observances) in the "Pessoas" (persons) section when creating or editing either a legal or a natural person.

    Published: 10 Jun 2025
    3.2
    Low

    CVE-2025-0036

    Last Modified: 15 Apr 2026

    In AMD Versal Adaptive SoC devices, the incorrect configuration of the SSS during runtime (post-boot) cryptographic operations could cause data to be incorrectly written to and read from invalid locations as well as returning incorrect cryptographic data.

    Published: 9 Jun 2025
    6.6
    Medium

    CVE-2025-0037

    Last Modified: 15 Apr 2026

    In AMD Versal Adaptive SoC devices, the lack of address validation when executing PLM runtime services through the PLM firmware can allow access to isolated or protected memory spaces, resulting in the loss of integrity and confidentiality.

    Published: 9 Jun 2025
    7.4
    High

    CVE-2025-5903

    Last Modified: 24 Jun 2025

    A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been classified as critical. Affected is the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument desc leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 9 Jun 2025
    7.4
    High

    CVE-2025-5902

    Last Modified: 24 Jun 2025

    A vulnerability was found in TOTOLINK T10 4.1.8cu.5207 and classified as critical. This issue affects the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument slaveIpList leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 9 Jun 2025
    9.3
    Critical

    CVE-2025-30515

    Last Modified: 12 Aug 2025

    CyberData 011209 Intercom could allow an authenticated attacker to upload arbitrary files to multiple locations within the system.

    Published: 9 Jun 2025
    7.4
    High

    CVE-2025-5901

    Last Modified: 24 Jun 2025

    A vulnerability has been found in TOTOLINK T10 4.1.8cu.5207 and classified as critical. This vulnerability affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument File leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 9 Jun 2025
    8.7
    High

    CVE-2025-30183

    Last Modified: 12 Aug 2025

    CyberData 011209 Intercom does not properly store or protect web server admin credentials.

    Published: 9 Jun 2025
    6.9
    Medium

    CVE-2025-30507

    Last Modified: 12 Aug 2025

    CyberData 011209 Intercom could allow an unauthenticated user to gather sensitive information through blind SQL injections.

    Published: 9 Jun 2025
    8.7
    High

    CVE-2025-26468

    Last Modified: 20 Jun 2025

    CyberData  011209 Intercom exposes features that could allow an unauthenticated to gain access and cause a denial-of-service condition or system disruption.

    Published: 9 Jun 2025
    9.3
    Critical

    CVE-2025-30184

    Last Modified: 12 Aug 2025

    CyberData 011209 Intercom could allow an unauthenticated user access to the Web Interface through an alternate path.

    Published: 9 Jun 2025
    2.1
    Low

    CVE-2025-5900

    Last Modified: 24 Jun 2025

    A vulnerability, which was classified as problematic, was found in Tenda AC9 15.03.02.13. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 9 Jun 2025
    1.9
    Low

    CVE-2025-5899

    Last Modified: 15 Apr 2026

    A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected by this vulnerability is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation leads to free of memory not on the heap. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

    Published: 9 Jun 2025
    1.9
    Low

    CVE-2025-5898

    Last Modified: 15 Apr 2026

    A vulnerability classified as critical has been found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation leads to out-of-bounds write. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

    Published: 9 Jun 2025
    7.5
    High

    CVE-2025-49140

    Last Modified: 15 Apr 2026

    Pion Interceptor is a framework for building RTP/RTCP communication software. Versions v0.1.36 through v0.1.38 contain a bug in a RTP packet factory that can be exploited to trigger a panic with Pion based SFU via crafted RTP packets, This only affect users that use pion/interceptor. Users should upgrade to v0.1.39 or later, which validates that: `padLen > 0 && padLen <= payloadLength` and return error on overflow, avoiding panic. If upgrading is not possible, apply the patch from the pull request manually or drop packets whose P-bit is set but whose padLen is zero or larger than the remaining payload.

    Published: 9 Jun 2025
    8.5
    High

    CVE-2025-49141

    Last Modified: 30 Jul 2025

    HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.3, the `gitImportSite` functionality obtains a URL string from a POST request and insufficiently validates user input. The `set_remote` function later passes this input into `proc_open`, yielding OS command injection. An authenticated attacker can craft a URL string that bypasses the validation checks employed by the `filter_var` and `strpos` functions in order to execute arbitrary OS commands on the backend server. The attacker can exfiltrate command output via an HTTP request. Version 11.0.3 contains a patch for the issue.

    Published: 9 Jun 2025