7.5
CVE-2025-64404 - Apache OpenOffice: Remote documents loaded without prompt via background and bullet images
Apache OpenOffice documents can contain links to other files. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of Apache OpenOffice, documents that used backgroun…
8.1
CVE-2025-64403 - Apache OpenOffice: Remote documents loaded without prompt via "external data sources" in Calc
Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause such links to be loaded without prompt. This issue affects Apache OpenOf…
6.5
CVE-2025-64402 - Apache OpenOffice: Remote documents loaded without prompt via OLE objects
Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of Apache OpenOffice, documents that used "OLE objects" linked to …
7.5
CVE-2025-64401 - Apache OpenOffice: Remote documents loaded without prompt via IFrame
Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of Apache OpenOffice, documents that used "floating frames" linked…
7.5
CVE-2025-12903 - Payment Plugins Braintree For WooCommerce <= 3.2.78 - Missing Authorization to Payment Token Exposu…
The Payment Plugins Braintree For WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wc-braintree/v1/3ds/vaulted_nonce REST API endpoint in all versions up to, and including, 3.2.78. This is due to the endpoint being registered with permi…
4.3
CVE-2025-12732 - WP Import – Ultimate CSV XML Importer for WordPress <= 7.33 - Missing Authorization to Authenticate…
The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of sensitive information due to a missing authorization check on the showsetting() function in all versions up to, and including, 7.33. This makes it possible for authenticated attacker…
8.7
CVE-2025-13047 - ViewLead Technology|Bacteriology Laboratory Reporting System
Bacteriology Laboratory Reporting System developed by ViewLead Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.
8.7
CVE-2025-13046 - ViewLead Technology|Bacteriology Laboratory Reporting System - SQL Injection
Bacteriology Laboratory Reporting System developed by ViewLead Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.
5.1
CVE-2025-12872 - aEnrich|eHRD - Stored Cross-Site Scripting
The a+HRD and a+HCM developed by aEnrich has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to upload files containing malicious JavaScript code, which will execute on the client side when a user is tricked into visiting a specific URL.
9.3
CVE-2025-12871 - aEnrich|a+HRD - Authentication Abuse
The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to craft administrator access tokens and use them to access the system with elevated privileges.