5.4

CVSS3.1

CVE-2025-42936 - Missing Authorization check in SAP NetWeaver Application Server for ABAP

The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations for different user roles, this issue allows authenticated users to access restricted objects in the barcode interface, leading to privilege escalation. This results in a low impact โ€ฆ

๐Ÿ“… Published: Aug. 12, 2025, 2:05 a.m. ๐Ÿ”„ Last Modified: Aug. 13, 2025, 3:03 p.m.

4.1

CVSS3.1

CVE-2025-42935 - Information Disclosure vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform(Internet Communโ€ฆ

The SAP NetWeaver Application Server ABAP and ABAP Platform Internet Communication Manager (ICM) permits authorized users with admin privileges and local access to log files to read sensitive information, resulting in information disclosure. This leads to high impact on the confidentiality of the aโ€ฆ

๐Ÿ“… Published: Aug. 12, 2025, 2:05 a.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 2:25 p.m.

4.3

CVSS3.1

CVE-2025-42934 - CRLF Injection vulnerability in SAP S/4HANA (Supplier invoice)

SAP S/4HANA Supplier invoice is vulnerable to CRLF Injection. An attacker with user-level privileges can bypass the allowlist and insert untrusted sites into the 'Trusted Sites' configuration by injecting line feed (LF) characters into application inputs. This vulnerability has a low impact on the โ€ฆ

๐Ÿ“… Published: Aug. 12, 2025, 2:04 a.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 2:25 p.m.

7.0

CVSS3.1

CVE-2025-38500 - xfrm: interface: fix use-after-free after changing collect_md xfrm interface

In the Linux kernel, the following vulnerability has been resolved: xfrm: interface: fix use-after-free after changing collect_md xfrm interface collect_md property on xfrm interfaces can only be set on device creation, thus xfrmi_changelink() should fail when called on such interfaces. The checโ€ฆ

๐Ÿ“… Published: Aug. 12, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 15, 2025, 3:16 p.m.

5.1

CVSS4.0

CVE-2025-55159 - slab allows out-of-bounds access in `get_disjoint_mut` due to incorrect bounds check

slab is a pre-allocated storage for a uniform data type. In version 0.4.10, the get_disjoint_mut method incorrectly checked if indices were within the slab's capacity instead of its length, allowing access to uninitialized memory. This could lead to undefined behavior or potential crashes. This hasโ€ฆ

๐Ÿ“… Published: Aug. 11, 2025, 11 p.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 2:25 p.m.

6.9

CVSS4.0

CVE-2025-55157 - Vim heap use-after-free vulnerability when processing recursive tuple data types

Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1400, When processing nested tuples in Vim script, an error during evaluation can trigger a use-after-free in Vimโ€™s internal tuple reference management. Specifically, the tuple_unref() function may access alreaโ€ฆ

๐Ÿ“… Published: Aug. 11, 2025, 10:54 p.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 6:50 p.m.

6.9

CVSS4.0

CVE-2025-55158 - Vim double-free vulnerability during Vim9 script import operations

Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1406, when processing nested tuples during Vim9 script import operations, an error during evaluation can trigger a double-free in Vimโ€™s internal typed value (typval_T) management. Specifically, the clear_tv() fโ€ฆ

๐Ÿ“… Published: Aug. 11, 2025, 10:54 p.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 6:49 p.m.

8.6

CVSS3.1

CVE-2025-55161 - Stirling-PDF SSRF vulnerability on /api/v1/convert/markdown/pdf

Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, when using the /api/v1/convert/markdown/pdf endpoint to convert Markdown to PDF, the backend calls a third-party tool to process it and includes a sanitizer for security sanitizatโ€ฆ

๐Ÿ“… Published: Aug. 11, 2025, 10:28 p.m. ๐Ÿ”„ Last Modified: Aug. 15, 2025, 6:05 p.m.

7.8

CVSS4.0

CVE-2025-55156 - PyLoad vulnerable to SQL Injection via API /json/add_package in add_links parameter

pyLoad is the free and open-source Download Manager written in pure Python. Prior to version 0.5.0b3.dev91, the parameter add_links in API /json/add_package is vulnerable to SQL Injection. Attackers can modify or delete data in the database, causing data errors or loss. This issue has been patched โ€ฆ

๐Ÿ“… Published: Aug. 11, 2025, 10:21 p.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 3:49 p.m.

8.6

CVSS3.1

CVE-2025-55150 - Stirling-PDF SSRF vulnerability on /api/v1/convert/html/pdf

Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, when using the /api/v1/convert/html/pdf endpoint to convert HTML to PDF, the backend calls a third-party tool to process it and includes a sanitizer for security sanitization whicโ€ฆ

๐Ÿ“… Published: Aug. 11, 2025, 9:57 p.m. ๐Ÿ”„ Last Modified: Aug. 15, 2025, 6:08 p.m.
Total resulsts: 305858
Page 101 of 30,586
ยซ previous page ยป next page
Filters