3.8

CVSS3.1

CVE-2025-8594 - Pz-LinkCard < 2.5.7 - Contributor+ SSRF

The Pz-LinkCard WordPress plugin before 2.5.7 does not validate a parameter before making a request to it, which could allow users with a role as low as Contributor to perform SSRF attack.

πŸ“… Published: Oct. 14, 2025, 6 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-10357 - Simple SEO < 2.0.32 - Contributor+ Stored XSS

The Simple SEO WordPress plugin before 2.0.32 does not sanitise and escape some parameters when outputing them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.

πŸ“… Published: Oct. 14, 2025, 6 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-10732 - SureForms – Drag and Drop Form Builder for WordPress <= 1.12.1 - Missing Authorization to Authentic…

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.12.1. This is due to improper access control implementation on the '/wp-json/sureforms/v1/srfm-global-settings' REST API endpoint. …

πŸ“… Published: Oct. 14, 2025, 5:24 a.m. πŸ”„ Last Modified: April 21, 2026, 2:30 a.m.

8.6

CVSS3.1

CVE-2025-59889 -

Improper authentication of library files in the Eaton IPP software installer could lead to arbitrary code execution of an attacker with the access to the software package.Β  This security issue has been fixed in the latest version of IPP which is available on the Eaton download center.

πŸ“… Published: Oct. 14, 2025, 5:11 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-42939 - Missing Authorization Check in SAP S/4HANA (Manage Processing Rules - For Bank Statements)

SAP S/4HANA (Manage Processing Rules - For Bank Statements) allows an authenticated attacker with basic privileges to delete conditions from any shared rule of any user by tampering the request parameter. Due to missing authorization check, the attacker can delete shared rule conditions that should…

πŸ“… Published: Oct. 14, 2025, 12:18 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-42937 - Directory Traversal vulnerability in SAP Print Service

SAP Print Service (SAPSprint) performs insufficient validation of path information provided by users. An unauthenticated attacker could traverse to the parent directory and over-write system files causing high impact on confidentiality integrity and availability of the application.

πŸ“… Published: Oct. 14, 2025, 12:18 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9

CVSS3.1

CVE-2025-42910 - Unrestricted File Upload Vulnerability in SAP Supplier Relationship Management

Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attacker to upload arbitrary files. These files could include executables which might be downloaded and executed by the user which could host malware. On successful exploitation an atta…

πŸ“… Published: Oct. 14, 2025, 12:18 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3

CVSS3.1

CVE-2025-42909 - Security Misconfiguration vulnerability in SAP Cloud Appliance Library Appliances

SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default profile setting in an existing SAP CAL appliances to gain access to other appliances. This has low impact on confidentiality of the application, integrity and availability is not i…

πŸ“… Published: Oct. 14, 2025, 12:18 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-42908 - Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP

Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP, an authenticated attacker could initiate transactions directly via the session manager, bypassing the first transaction screen and the associated authorization check. This vulnerability could allo…

πŸ“… Published: Oct. 14, 2025, 12:18 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-42906 - Directory Traversal vulnerability in SAP Commerce Cloud

SAP Commerce Cloud contains a path traversal vulnerability that may allow users to access web applications such as the Administration Console from addresses where the Administration Console is not explicitly deployed. This could potentially bypass configured access restrictions, resulting in a low …

πŸ“… Published: Oct. 14, 2025, 12:17 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3453 of 34,919
Β« previous page Β» next page
Filters