CVE Feed

    Dashboard / CVE

    8.6
    High

    CVE-2025-25243

    Last Modified: 15 Apr 2026

    SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a publicly available servlet to download an arbitrary file over the network without any user interaction. This can reveal highly sensitive information with no impact to integrity or availability.

    Published: 11 Feb 2025
    5.4
    Medium

    CVE-2025-25241

    Last Modified: 15 Apr 2026

    Due to a missing authorization check, an attacker who is logged in to application can view/ delete �My Overtime Requests� which could allow the attacker to access employee information. This leads to low impact on confidentiality, integrity of the application. There is no impact on availability.

    Published: 11 Feb 2025
    8.1
    High

    CVE-2025-24876

    Last Modified: 15 Apr 2026

    The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an authorization code an attacker can steal the session of the victim by injecting malicious payload causing High impact on confidentiality and integrity of the application

    Published: 11 Feb 2025
    6.8
    Medium

    CVE-2025-24875

    Last Modified: 15 Apr 2026

    SAP Commerce, by default, sets certain cookies with the SameSite attribute configured to None (SameSite=None). This includes authentication cookies utilized in SAP Commerce Backoffice. Applying this setting reduces defense in depth against CSRF and may lead to future compatibility issues.

    Published: 11 Feb 2025
    6.8
    Medium

    CVE-2025-24874

    Last Modified: 15 Apr 2026

    SAP Commerce (Backoffice) uses the deprecated X-FRAME-OPTIONS header to protect against clickjacking. While this protection remains effective now, it may not be the case in the future as browsers might discontinue support for this header in favor of the frame-ancestors CSP directive. Hence, clickjacking could become possible then, and lead to exposure and modification of sensitive information.

    Published: 11 Feb 2025
    4.3
    Medium

    CVE-2025-24872

    Last Modified: 15 Apr 2026

    The ABAP Build Framework in SAP ABAP Platform allows an authenticated attacker to gain unauthorized access to a specific transaction. By executing the add-on build functionality within the ABAP Build Framework, an attacker could call the transaction and view its details. This has a limited impact on the confidentiality of the application with no effect on the integrity and availability of the application.

    Published: 11 Feb 2025
    6
    Medium

    CVE-2025-24870

    Last Modified: 15 Apr 2026

    SAP GUI for Windows & RFC service credentials are incorrectly stored in the memory of the program allowing an unauthenticated attacker to access information within systems, resulting in privilege escalation. On successful exploitation, this could result in disclosure of highly sensitive information. This has no impact on integrity, and availability.

    Published: 11 Feb 2025
    4.3
    Medium

    CVE-2025-24869

    Last Modified: 15 Apr 2026

    SAP NetWeaver Application Server Java allows an attacker to access an endpoint that can disclose information about deployed server components, including their XML definitions. This information should ideally be restricted to customer administrators, even though they may not need it. These XML files are not entirely SAP-internal as they are deployed with the server. In such a scenario, sensitive information could be exposed without compromising its integrity or availability.

    Published: 11 Feb 2025
    7.1
    High

    CVE-2025-24868

    Last Modified: 15 Apr 2026

    The User Account and Authentication service (UAA) for SAP HANA extended application services, advanced model (SAP HANA XS advanced model) allows an unauthenticated attacker to craft a malicious link, that, when clicked by a victim, redirects the browser to a malicious site due to insufficient redirect URL validation. On successful exploitation attacker can cause limited impact on confidentiality, integrity, and availability of the system.

    Published: 11 Feb 2025
    6.1
    Medium

    CVE-2025-24867

    Last Modified: 15 Apr 2026

    SAP BusinessObjects Platform (BI Launchpad) does not sufficiently handle user input, resulting in Cross-Site Scripting (XSS) vulnerability. The application allows an unauthenticated attacker to craft a URL that embeds a malicious script within an unprotected parameter. When a victim clicks the link, the script will be executed in the browser, giving the attacker the ability to access and/or modify information related to the web client with no effect on availability.

    Published: 11 Feb 2025
    5.3
    Medium

    CVE-2025-23193

    Last Modified: 23 Oct 2025

    SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respond differently based on the existence of a specified user, potentially revealing sensitive information. This issue does not enable data modification and has no impact on server availability.

    Published: 11 Feb 2025
    3.1
    Low

    CVE-2025-23191

    Last Modified: 15 Apr 2026

    Cached values belonging to the SAP OData endpoint in SAP Fiori for SAP ERP could be poisoned by modifying the Host header value in an HTTP GET request. An attacker could alter the `atom:link` values in the returned metadata redirecting them from the SAP server to a malicious link set by the attacker. Successful exploitation could cause low impact on integrity of the application.

    Published: 11 Feb 2025
    4.3
    Medium

    CVE-2025-23190

    Last Modified: 15 Apr 2026

    Due to missing authorization check, an authenticated attacker could call a remote-enabled function module which allows them to access data that they would otherwise not have access to. The attacker cannot modify data or impact the availability of the system.

    Published: 11 Feb 2025
    4.3
    Medium

    CVE-2025-23189

    Last Modified: 15 Apr 2026

    Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an authenticated attacker could generate technical meta-data. This leads to a low impact on integrity. There is no impact on confidentiality or availability

    Published: 11 Feb 2025
    5.3
    Medium

    CVE-2025-23187

    Last Modified: 15 Apr 2026

    Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an unauthenticated attacker could generate technical meta-data. This leads to a low impact on integrity. There is no impact on confidentiality or availability.

    Published: 11 Feb 2025
    8.7
    High

    CVE-2025-0064

    Last Modified: 23 Oct 2025

    Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intelligence platform allows an attacker with admin rights to generate or retrieve a secret passphrase, enabling them to impersonate any user in the system. This results in a high impact on confidentiality and integrity, with no impact on availability.

    Published: 11 Feb 2025
    5.4
    Medium

    CVE-2025-0054

    Last Modified: 15 Apr 2026

    SAP NetWeaver Application Server Java does not sufficiently handle user input, resulting in a stored cross-site scripting vulnerability. The application allows attackers with basic user privileges to store a Javascript payload on the server, which could be later executed in the victim's web browser. With this the attacker might be able to read or modify information associated with the vulnerable web page.

    Published: 11 Feb 2025
    6.9
    Medium

    CVE-2025-1165

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as critical, was found in Lumsoft ERP 8. Affected is the function DoUpload/DoWebUpload of the file /Api/FileUploadApi.ashx. The manipulation of the argument file leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Feb 2025
    4.8
    Medium

    CVE-2025-1164

    Last Modified: 11 Apr 2025

    A vulnerability, which was classified as problematic, has been found in code-projects Police FIR Record Management System 1.0. This issue affects some unknown processing of the component Add Record Handler. The manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.

    Published: 11 Feb 2025
    5.1
    Medium

    CVE-2025-25525

    Last Modified: 15 Apr 2026

    Buffer overflow vulnerability in H3C FA3010L access points SWFA1B0V100R005 due to the lack of length verification, which is related to the setting of firewall rules. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.

    Published: 11 Feb 2025
    6.8
    Medium

    CVE-2024-54916

    Last Modified: 15 Apr 2026

    An issue in the SharedConfig class of Telegram Android APK v.11.7.0 allows a physically proximate attacker to bypass authentication and escalate privileges by manipulating the return value of the checkPasscode method.

    Published: 11 Feb 2025
    5.1
    Medium

    CVE-2022-35202

    Last Modified: 15 Apr 2026

    A security issue in Sitevision version 10.3.1 and older allows a remote attacker, in certain (non-default) scenarios, to gain access to the private keys used for signing SAML Authn requests. The underlying issue is a Java keystore that may become accessible and downloadable via WebDAV. This keystore is protected with a low-complexity, auto-generated password.

    Published: 11 Feb 2025
    9.8
    Critical

    CVE-2025-25530

    Last Modified: 15 Apr 2026

    Buffer overflow vulnerability in Digital China DCBI-Netlog-LAB Gateway 1.0 due to the lack of length verification, which is related to saving parental control configuration information. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.

    Published: 11 Feb 2025
    5.1
    Medium

    CVE-2025-25528

    Last Modified: 7 Oct 2025

    Multiple buffer overflow vulnerabilities in Wavlink WL-WN575A3 RPT75A3.V4300, which are caused by not performing strict length checks on user-controlled data. By successfully exploiting the vulnerabilities, attackers can crash the remote devices or execute arbitrary commands without any authorization verification.

    Published: 11 Feb 2025
    5.1
    Medium

    CVE-2025-25527

    Last Modified: 13 Aug 2025

    Buffer overflow vulnerability in Ruijie RG-NBR2600S Gateway 10.3(4b12) due to the lack of length verification, which is related to the configuration of source address NAT rules. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.

    Published: 11 Feb 2025
    5.4
    Medium

    CVE-2024-54772

    Last Modified: 30 Jun 2025

    An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available in the stable release v6.49.18. A discrepancy in response size between connection attempts made with a valid username and those with an invalid username allows attackers to enumerate for valid accounts.

    Published: 11 Feb 2025
    7.3
    High

    CVE-2025-25522

    Last Modified: 6 Jun 2025

    Buffer overflow vulnerability in Linksys WAP610N v1.0.05.002 due to the lack of length verification, which is related to the time setting operation. The attacker can directly control the remote target device by successfully exploiting this vulnerability.

    Published: 11 Feb 2025
    3.8
    Low

    CVE-2024-51324

    Last Modified: 15 Apr 2026

    An issue in the BdApiUtil driver of Baidu Antivirus v5.2.3.116083 allows attackers to terminate arbitrary process via executing a BYOVD (Bring Your Own Vulnerable Driver) attack.

    Published: 11 Feb 2025
    6.5
    Medium

    CVE-2022-37660

    Last Modified: 3 Nov 2025

    In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association. An attacker that successfully bootstrapped public keys with another entity using PKEX in the past, will be able to subvert a future bootstrapping by passively observing public keys, re-using the encrypting element Qi and subtracting it from the captured message M (X = M - Qi). This will result in the public ephemeral key X; the only element required to subvert the PKEX association.

    Published: 11 Feb 2025
    7.9
    High

    CVE-2024-33469

    Last Modified: 15 Apr 2026

    An issue in Team Amaze Amaze File Manager v.3.8.5 and fixed in v.3.10 allows a local attacker to execute arbitrary code via the onCreate method of DatabaseViewerActivity.java.

    Published: 11 Feb 2025
    5.3
    Medium

    CVE-2024-44336

    Last Modified: 15 Apr 2026

    An issue in AnkiDroid Android Application v2.17.6 allows attackers to retrieve internal files from the /data/data/com.ichi2.anki/ directory and save it into publicly available storage.

    Published: 11 Feb 2025
    6.5
    Medium

    CVE-2024-55212

    Last Modified: 15 Apr 2026

    DNNGo xBlog v6.5.0 was discovered to contain a SQL injection vulnerability via the Categorys parameter at /DNNGo_xBlog/Resource_Service.aspx.

    Published: 11 Feb 2025
    —
    Unknown

    CVE-2024-57000

    Last Modified: 14 Feb 2025

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-48022. Reason: This candidate is a duplicate of CVE-2023-48022. Notes: All CVE users should reference CVE-2023-48022 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 11 Feb 2025
    6.5
    Medium

    CVE-2024-57241

    Last Modified: 1 Apr 2025

    Dedecms 5.71sp1 and earlier is vulnerable to URL redirect. In the web application, a logic error does not judge the input GET request resulting in URL redirection.

    Published: 11 Feb 2025
    5.1
    Medium

    CVE-2024-57777

    Last Modified: 23 Oct 2025

    Directory Traversal vulnerability in Ianproxy v.0.1 and before allows a remote attacker to obtain sensitive information

    Published: 11 Feb 2025
    5.1
    Medium

    CVE-2025-25529

    Last Modified: 15 Apr 2026

    Buffer overflow vulnerability in Digital China DCBC Gateway 200-2.1.1 due to the lack of length verification, which is related to the configuration of static NAT rules. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.

    Published: 11 Feb 2025
    5.1
    Medium

    CVE-2025-25526

    Last Modified: 15 Apr 2026

    Buffer overflow vulnerability in Mercury MIPC552W Camera v1.0 due to the lack of length verification, which is related to the configuration of the PPTP server. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.

    Published: 11 Feb 2025
    5.9
    Medium

    CVE-2025-25523

    Last Modified: 23 May 2025

    Buffer overflow vulnerability in Trendnet TEG-40128 Web Smart Switch v1(1.00.023) due to the lack of length verification, which is related to the mobile access point setup operation. The attacker can directly control the remote target device by successfully exploiting this vulnerability.

    Published: 11 Feb 2025
    5.1
    Medium

    CVE-2025-25524

    Last Modified: 29 Apr 2025

    Buffer overflow vulnerability in TOTOLink X6000R routers V9.4.0cu.652_B20230116 due to the lack of length verification, which is related to the addition of Wi-Fi filtering rules. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.

    Published: 11 Feb 2025
    4.8
    Medium

    CVE-2025-1163

    Last Modified: 10 Apr 2025

    A vulnerability classified as critical was found in code-projects Vehicle Parking Management System 1.0. This vulnerability affects the function login of the component Authentication. The manipulation of the argument username leads to stack-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

    Published: 10 Feb 2025
    5.3
    Medium

    CVE-2025-1162

    Last Modified: 28 May 2025

    A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0. This affects an unknown part of the file /\_parse/load\_user-profile.php. The manipulation of the argument userhash leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 10 Feb 2025
    6.9
    Medium

    CVE-2025-1160

    Last Modified: 3 Mar 2025

    A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php. The manipulation of the argument username/password leads to use of default credentials. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 10 Feb 2025
    4
    Medium

    CVE-2025-25194

    Last Modified: 15 Apr 2026

    Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on activitypub_federation, a framework for ActivityPub federation in Rust. This vulnerability, which is present in versions 0.6.2 and prior of activitypub_federation and versions 0.19.8 and prior of Lemmy, allows a user to bypass any predefined hardcoded URL path or security anti-Localhost mechanism and perform an arbitrary GET request to any Host, Port and URL using a Webfinger Request. As of time of publication, a fix has not been made available.

    Published: 10 Feb 2025
    5.5
    Medium

    CVE-2025-25190

    Last Modified: 15 Apr 2026

    The ZOO-Project is an open source processing platform. The ZOO-Project Web Processing Service (WPS) Server contains a Cross-Site Scripting (XSS) vulnerability in its EchoProcess service prior to commit 7a5ae1a. The vulnerability exists because the EchoProcess service directly reflects user input in its output without proper sanitization when handling complex inputs.The service accepts various input formats including XML, JSON, and SVG, and returns the content based on the requested MIME type. When processing SVG content and returning it with the image/svg+xml MIME type, the server fails to sanitize potentially malicious JavaScript in attributes like onload, allowing arbitrary JavaScript execution in the victim's browser context. This vulnerability is particularly dangerous because it exists in a service specifically designed to echo back user input, and the lack of proper sanitization in combination with SVG handling creates a reliable XSS vector. Commit 7a5ae1a contains a fix for the issue.

    Published: 10 Feb 2025
    5.5
    Medium

    CVE-2025-25189

    Last Modified: 15 Apr 2026

    The ZOO-Project is an open source processing platform. A reflected Cross-Site Scripting vulnerability exists in the ZOO-Project Web Processing Service (WPS) publish.py CGI script prior to commit 7a5ae1a. The script reflects user input from the `jobid` parameter in its HTTP response without proper HTML encoding or sanitization. When a victim visits a specially crafted URL pointing to this endpoint, arbitrary JavaScript code can be executed in their browser context. The vulnerability occurs because the CGI script directly outputs the query string parameters into the HTML response without escaping HTML special characters. An attacker can inject malicious JavaScript code through the `jobid` parameter which will be executed when rendered by the victim's browser. Commit 7a5ae1a contains a fix for the issue.

    Published: 10 Feb 2025
    5.5
    Medium

    CVE-2025-25193

    Last Modified: 11 Jun 2025

    Netty, an asynchronous, event-driven network application framework, has a vulnerability in versions up to and including 4.1.118.Final. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application, Netty attempts to load a file that does not exist. If an attacker creates such a large file, the Netty application crash. A similar issue was previously reported as CVE-2024-47535. This issue was fixed, but the fix was incomplete in that null-bytes were not counted against the input limit. Commit d1fbda62d3a47835d3fb35db8bd42ecc205a5386 contains an updated fix.

    Published: 10 Feb 2025
    5.1
    Medium

    CVE-2025-1159

    Last Modified: 28 Mar 2025

    A vulnerability was found in CampCodes School Management Software 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /academic-calendar. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 10 Feb 2025
    7.5
    High

    CVE-2025-24970

    Last Modified: 5 Sept 2025

    Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead to a native crash. Version 4.1.118.Final contains a patch. As workaround its possible to either disable the usage of the native SSLEngine or change the code manually.

    Published: 10 Feb 2025
    5.3
    Medium

    CVE-2025-1158

    Last Modified: 15 Apr 2026

    A vulnerability was found in ESAFENET CDG 5.6.3.154.205_20250114. It has been classified as critical. Affected is an unknown function of the file addPolicyToSafetyGroup.jsp. The manipulation of the argument safetyGroupId leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 10 Feb 2025
    5.3
    Medium

    CVE-2025-1157

    Last Modified: 15 Apr 2026

    A vulnerability was found in Allims lab.online up to 20250201 and classified as critical. This issue affects some unknown processing of the file /model/model_recuperar_senha.php. The manipulation of the argument recuperacao leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 10 Feb 2025