7.5

CVSS3.1

CVE-2025-64404 - Apache OpenOffice: Remote documents loaded without prompt via background and bullet images

Apache OpenOffice documents can contain links to other files. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of Apache OpenOffice, documents that used backgroun…

📅 Published: Nov. 12, 2025, 9:08 a.m. 🔄 Last Modified: Nov. 13, 2025, 5:15 p.m.

8.1

CVSS3.1

CVE-2025-64403 - Apache OpenOffice: Remote documents loaded without prompt via "external data sources" in Calc

Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause such links to be loaded without prompt. This issue affects Apache OpenOf…

📅 Published: Nov. 12, 2025, 9:04 a.m. 🔄 Last Modified: Nov. 13, 2025, 3:08 p.m.

6.5

CVSS3.1

CVE-2025-64402 - Apache OpenOffice: Remote documents loaded without prompt via OLE objects

Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of Apache OpenOffice, documents that used "OLE objects" linked to …

📅 Published: Nov. 12, 2025, 9:03 a.m. 🔄 Last Modified: Nov. 13, 2025, 3:08 p.m.

7.5

CVSS3.1

CVE-2025-64401 - Apache OpenOffice: Remote documents loaded without prompt via IFrame

Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of Apache OpenOffice, documents that used "floating frames" linked…

📅 Published: Nov. 12, 2025, 8:58 a.m. 🔄 Last Modified: Nov. 13, 2025, 3:09 p.m.

7.5

CVSS3.1

CVE-2025-12903 - Payment Plugins Braintree For WooCommerce <= 3.2.78 - Missing Authorization to Payment Token Exposu…

The Payment Plugins Braintree For WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wc-braintree/v1/3ds/vaulted_nonce REST API endpoint in all versions up to, and including, 3.2.78. This is due to the endpoint being registered with permi…

📅 Published: Nov. 12, 2025, 8:28 a.m. 🔄 Last Modified: Nov. 12, 2025, 10:12 p.m.

4.3

CVSS3.1

CVE-2025-12732 - WP Import – Ultimate CSV XML Importer for WordPress <= 7.33 - Missing Authorization to Authenticate…

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of sensitive information due to a missing authorization check on the showsetting() function in all versions up to, and including, 7.33. This makes it possible for authenticated attacker…

📅 Published: Nov. 12, 2025, 8:28 a.m. 🔄 Last Modified: Nov. 12, 2025, 10:12 p.m.

8.7

CVSS4.0

CVE-2025-13047 - ViewLead Technology|Bacteriology Laboratory Reporting System

Bacteriology Laboratory Reporting System developed by ViewLead Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

📅 Published: Nov. 12, 2025, 7:59 a.m. 🔄 Last Modified: Nov. 12, 2025, 10:12 p.m.

8.7

CVSS4.0

CVE-2025-13046 - ViewLead Technology|Bacteriology Laboratory Reporting System - SQL Injection

Bacteriology Laboratory Reporting System developed by ViewLead Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

📅 Published: Nov. 12, 2025, 7:57 a.m. 🔄 Last Modified: Nov. 12, 2025, 10:12 p.m.

5.1

CVSS4.0

CVE-2025-12872 - aEnrich|eHRD - Stored Cross-Site Scripting

The a+HRD and a+HCM developed by aEnrich has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to upload files containing malicious JavaScript code, which will execute on the client side when a user is tricked into visiting a specific URL.

📅 Published: Nov. 12, 2025, 7:47 a.m. 🔄 Last Modified: Nov. 12, 2025, 10:12 p.m.

9.3

CVSS4.0

CVE-2025-12871 - aEnrich|a+HRD - Authentication Abuse

The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to craft administrator access tokens and use them to access the system with elevated privileges.

📅 Published: Nov. 12, 2025, 7:38 a.m. 🔄 Last Modified: Nov. 18, 2025, 6:28 p.m.
Total resulsts: 342379
Page 2360 of 34,238
« previous page » next page
Filters