CVE Feed

    Dashboard / CVE

    6.6
    Medium

    CVE-2025-31332

    Last Modified: 24 Oct 2025

    Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker who has local access to the system could modify files potentially disrupting operations or cause service downtime hence leading to a high impact on integrity and availability. However, this vulnerability does not disclose any sensitive data.

    Published: 8 Apr 2025
    4.3
    Medium

    CVE-2025-31331

    Last Modified: 15 Apr 2026

    SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would normally require additional validation. Once logged into the ABAP system, the attacker can run a specific transaction that exposes sensitive system code without proper authorization. This vulnerability compromises the confidentiality.

    Published: 8 Apr 2025
    9.9
    Critical

    CVE-2025-31330

    Last Modified: 15 Apr 2026

    SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.

    Published: 8 Apr 2025
    4.4
    Medium

    CVE-2025-30017

    Last Modified: 15 Apr 2026

    Due to a missing authorization check, an authenticated attacker could upload a file as a template for solution documentation in SAP Solution Manager 7.1. After successful exploitation, an attacker can cause limited impact on the integrity and availability of the application.

    Published: 8 Apr 2025
    9.8
    Critical

    CVE-2025-30016

    Last Modified: 15 Apr 2026

    SAP Financial Consolidation allows an unauthenticated attacker to gain unauthorized access to the Admin account. The vulnerability arises due to improper authentication mechanisms, due to which there is high impact on the Confidentiality, Integrity & Availability of the application.

    Published: 8 Apr 2025
    4.1
    Medium

    CVE-2025-30015

    Last Modified: 15 Apr 2026

    Due to incorrect memory address handling in ABAP SQL of SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker with high privileges could execute certain forms of SQL queries leading to manipulation of content in the output variable. This vulnerability has a low impact on the confidentiality, integrity and the availability of the application.

    Published: 8 Apr 2025
    7.7
    High

    CVE-2025-30014

    Last Modified: 15 Apr 2026

    SAP Capital Yield Tax Management has directory traversal vulnerability due to insufficient path validation. This could allow an attacker with low privileges to read files from directory which they don�t have access to, hence causing a high impact on confidentiality. Integrity and Availability are not affected.

    Published: 8 Apr 2025
    6.7
    Medium

    CVE-2025-30013

    Last Modified: 15 Apr 2026

    SAP ERP BW Business Content is vulnerable to OS Command Injection through certain function modules. These function modules, when executed with elevated privileges, improperly handle user input, allowing attacker to inject arbitrary OS commands. This vulnerability allows the execution of unintended commands on the underlying system, posing a significant security risk to the confidentiality, integrity and availability of the application.

    Published: 8 Apr 2025
    4.3
    Medium

    CVE-2025-27437

    Last Modified: 15 Apr 2026

    A Missing Authorization Check vulnerability exists in the Virus Scanner Interface of SAP NetWeaver Application Server ABAP. Because of this, an attacker authenticated as a non-administrative user can initiate a transaction, allowing them to access but not modify non-sensitive data without further authorization and with no effect on availability.

    Published: 8 Apr 2025
    4.2
    Medium

    CVE-2025-27435

    Last Modified: 15 Apr 2026

    Under specific conditions and prerequisites, an unauthenticated attacker could access customer coupon codes exposed in the URL parameters of the Coupon Campaign URL in SAP Commerce. This could allow the attacker to use the disclosed coupon code, hence posing a low impact on confidentiality and integrity of the application.

    Published: 8 Apr 2025
    9.9
    Critical

    CVE-2025-27429

    Last Modified: 15 Apr 2026

    SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.

    Published: 8 Apr 2025
    7.7
    High

    CVE-2025-27428

    Last Modified: 15 Apr 2026

    Due to directory traversal vulnerability, an authorized attacker could gain access to some critical information by using RFC enabled function module. Upon successful exploitation, they could read files from any managed system connected to SAP Solution Manager, leading to high impact on confidentiality. There is no impact on integrity or availability.

    Published: 8 Apr 2025
    5.3
    Medium

    CVE-2025-26657

    Last Modified: 15 Apr 2026

    SAP KMC WPC allows an unauthenticated attacker to remotely retrieve usernames by a simple parameter query which could expose sensitive information causing low impact on confidentiality of the application. This has no effect on integrity and availability.

    Published: 8 Apr 2025
    6.8
    Medium

    CVE-2025-26654

    Last Modified: 15 Apr 2026

    SAP Commerce Cloud (Public Cloud) does not allow to disable unencrypted HTTP (port 80) entirely, but instead allows a redirect from port 80 to 443 (HTTPS). As a result, Commerce normally communicates securely over HTTPS. However, the confidentiality and integrity of data sent on the first request before the redirect may be impacted if the client is configured to use HTTP and sends confidential data on the first request before the redirect.

    Published: 8 Apr 2025
    4.7
    Medium

    CVE-2025-26653

    Last Modified: 15 Apr 2026

    SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an attacker, without requiring any privileges, to inject malicious JavaScript into a website. When a user visits the compromised page, the injected script gets executed, potentially compromising the confidentiality and integrity within the scope of the victim�s browser. Availability is not impacted.

    Published: 8 Apr 2025
    8.5
    High

    CVE-2025-23186

    Last Modified: 15 Apr 2026

    In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, which can be used to expose credentials for a remote service. These credentials can then be further exploited to completely compromise the remote service, potentially resulting in a significant impact on the confidentiality, integrity, and availability of the application.

    Published: 8 Apr 2025
    4.9
    Medium

    CVE-2025-3428

    Last Modified: 21 Apr 2026

    The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'coating_text' parameter in all versions up to, and including, 2.1.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 8 Apr 2025
    4.9
    Medium

    CVE-2019-25223

    Last Modified: 15 Apr 2026

    The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 8 Apr 2025
    4.9
    Medium

    CVE-2025-3430

    Last Modified: 21 Apr 2026

    The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'printer_text' parameter in all versions up to, and including, 2.1.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 8 Apr 2025
    4.9
    Medium

    CVE-2025-3429

    Last Modified: 21 Apr 2026

    The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'material_text' parameter in all versions up to, and including, 2.1.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 8 Apr 2025
    4.9
    Medium

    CVE-2025-3427

    Last Modified: 22 Apr 2026

    The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'infill_text' parameter in all versions up to, and including, 2.1.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 8 Apr 2025
    5.3
    Medium

    CVE-2025-3413

    Last Modified: 16 Oct 2025

    A vulnerability has been found in opplus springboot-admin up to a2d5310f44fd46780a8686456cf2f9001ab8f024 and classified as critical. Affected by this vulnerability is the function code of the file SysGeneratorController.java. The manipulation of the argument Tables leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Apr 2025
    4.3
    Medium

    CVE-2025-0361

    Last Modified: 14 Jan 2026

    During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed for unauthenticated username enumeration through the VAPIX Device Configuration SSH Management API.

    Published: 8 Apr 2025
    4.3
    Medium

    CVE-2024-47261

    Last Modified: 14 Jan 2026

    51l3nc3, a member of the AXIS OS Bug Bounty Program, has found that the VAPIX API uploadoverlayimage.cgi did not have sufficient input validation to allow an attacker to upload files to block access to create image overlays in the web interface of the Axis device.

    Published: 8 Apr 2025
    5.3
    Medium

    CVE-2025-3412

    Last Modified: 4 Sept 2025

    A vulnerability, which was classified as critical, was found in mymagicpower AIAS 20250308. Affected is an unknown function of the file 2_training_platform/train-platform/src/main/java/top/aias/training/controller/InferController.java. The manipulation of the argument url leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Apr 2025
    5.3
    Medium

    CVE-2025-3411

    Last Modified: 4 Sept 2025

    A vulnerability, which was classified as critical, has been found in mymagicpower AIAS 20250308. This issue affects some unknown processing of the file 3_api_platform/api-platform/src/main/java/top/aias/platform/controller/AsrController.java. The manipulation of the argument url leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Apr 2025
    5.3
    Medium

    CVE-2025-3410

    Last Modified: 4 Sept 2025

    A vulnerability classified as critical was found in mymagicpower AIAS 20250308. This vulnerability affects unknown code of the file training_platform/train-platform/src/main/java/top/aias/training/controller/LocalStorageController.java. The manipulation of the argument File leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Apr 2025
    8.8
    High

    CVE-2025-20946

    Last Modified: 26 Feb 2026

    Improper handling of exceptional conditions in pairing specific bluetooth devices in Galaxy Watch Bluetooth pairing prior to SMR Apr-2025 Release 1 allows local attackers to pair with specific bluetooth devices without user interaction.

    Published: 8 Apr 2025
    5.4
    Medium

    CVE-2025-20939

    Last Modified: 27 Jan 2026

    Improper authorization in wireless download protocol in Galaxy Watch prior to SMR Apr-2025 Release 1 allows physical attackers to update device unique identifier of Watch devices.

    Published: 8 Apr 2025
    5.1
    Medium

    CVE-2025-20951

    Last Modified: 17 Jul 2025

    Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows local attackers to write arbitrary files with the privilege of Galaxy Store.

    Published: 8 Apr 2025
    4
    Medium

    CVE-2025-20950

    Last Modified: 17 Jul 2025

    Use of implicit intent for sensitive communication in SamsungNotes prior to version 4.4.26.45 allows local attackers to access sensitive information.

    Published: 8 Apr 2025
    5.5
    Medium

    CVE-2025-20948

    Last Modified: 5 Feb 2026

    Out-of-bounds read in enrollment with cdsp frame secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to read out-of-bounds memory.

    Published: 8 Apr 2025
    5.5
    Medium

    CVE-2025-20947

    Last Modified: 5 Feb 2026

    Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access image files across multiple users. User interaction is required for triggering this vulnerability.

    Published: 8 Apr 2025
    4
    Medium

    CVE-2025-20945

    Last Modified: 27 Jan 2026

    Improper access control in Galaxy Watch prior to SMR Apr-2025 Release 1 allows local attackers to access sensitive information of Galaxy watch.

    Published: 8 Apr 2025
    6.2
    Medium

    CVE-2025-20944

    Last Modified: 5 Feb 2026

    Out-of-bounds read in parsing audio data in libsavsac.so prior to SMR Apr-2025 Release 1 allows local attackers to read out-of-bounds memory.

    Published: 8 Apr 2025
    6.4
    Medium

    CVE-2025-20943

    Last Modified: 5 Feb 2026

    Out-of-bounds write in secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to cause memory corruption.

    Published: 8 Apr 2025
    4.4
    Medium

    CVE-2025-20942

    Last Modified: 5 Feb 2026

    Improper Verification of Intent by Broadcast Receiver in DeviceIdService prior to SMR Apr-2025 Release 1 allows local attackers to reset OAID.

    Published: 8 Apr 2025
    6.2
    Medium

    CVE-2025-20941

    Last Modified: 5 Feb 2026

    Improper access control in InputManager to SMR Apr-2025 Release 1 allows local attackers to access the scancode of specific input device.

    Published: 8 Apr 2025
    4
    Medium

    CVE-2025-20940

    Last Modified: 15 Apr 2026

    Improper handling of insufficient permission in Samsung Device Health Manager Service prior to SMR Apr-2025 Release 1 allows local attackers to access provider in SDMHS.

    Published: 8 Apr 2025
    5.5
    Medium

    CVE-2025-20938

    Last Modified: 5 Feb 2026

    Improper access control in SamsungContacts prior to SMR Apr-2025 Release 1 allows local attackers to access protected data in SamsungContacts.

    Published: 8 Apr 2025
    8.8
    High

    CVE-2025-20936

    Last Modified: 26 Feb 2026

    Improper access control in HDCP trustlet prior to SMR Apr-2025 Release 1 allows local attackers with shell privilege to escalate their privileges to root.

    Published: 8 Apr 2025
    5.5
    Medium

    CVE-2025-20935

    Last Modified: 15 Apr 2026

    Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access files with system privilege. User interaction is required for triggering this vulnerability.

    Published: 8 Apr 2025
    5.5
    Medium

    CVE-2025-20934

    Last Modified: 30 Apr 2025

    Improper access control in Sticker Center prior to SMR Apr-2025 Release 1 allows local attackers to access image files with system privilege.

    Published: 8 Apr 2025
    5.3
    Medium

    CVE-2025-3409

    Last Modified: 16 Oct 2025

    A vulnerability classified as critical has been found in Nothings stb up to f056911. This affects the function stb_include_string. The manipulation of the argument path_to_includes leads to stack-based buffer overflow. It is possible to initiate the attack remotely. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Apr 2025
    9.1
    Critical

    CVE-2025-2004

    Last Modified: 20 Apr 2026

    The Simple WP Events plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wpe_delete_file AJAX action in all versions up to, and including, 1.8.17. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). CVE-2025-32509 is a duplicate of this.

    Published: 8 Apr 2025
    5.3
    Medium

    CVE-2024-13820

    Last Modified: 15 Apr 2026

    The Melhor Envio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.15.11 via the 'run' function, which uses a hardcoded hash. This makes it possible for unauthenticated attackers to extract sensitive data including environment information, plugin tokens, shipping configurations, and limited vendor information.

    Published: 8 Apr 2025
    5.3
    Medium

    CVE-2025-3408

    Last Modified: 16 Oct 2025

    A vulnerability was found in Nothings stb up to f056911. It has been rated as critical. Affected by this issue is the function stb_dupreplace. The manipulation leads to integer overflow. The attack may be launched remotely. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Apr 2025
    5.3
    Medium

    CVE-2025-3407

    Last Modified: 16 Oct 2025

    A vulnerability was found in Nothings stb up to f056911. It has been declared as critical. Affected by this vulnerability is the function stbhw_build_tileset_from_image. The manipulation of the argument h_count/v_count leads to out-of-bounds read. The attack can be launched remotely. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Apr 2025
    5.3
    Medium

    CVE-2025-3406

    Last Modified: 16 Oct 2025

    A vulnerability was found in Nothings stb up to f056911. It has been classified as problematic. Affected is the function stbhw_build_tileset_from_image of the component Header Array Handler. The manipulation of the argument w leads to out-of-bounds read. It is possible to launch the attack remotely. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Apr 2025
    5.3
    Medium

    CVE-2025-3405

    Last Modified: 15 Apr 2026

    A vulnerability was found in FCJ Venture Builder appclientefiel 3.0.27. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /rest/cliente/ObterPedido/ of the component HTTP GET Request Handler. The manipulation of the argument ORDER_ID leads to improper control of resource identifiers. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Apr 2025