3.8
CVE-2025-8594 - Pz-LinkCard < 2.5.7 - Contributor+ SSRF
The Pz-LinkCard WordPress plugin before 2.5.7 does not validate a parameter before making a request to it, which could allow users with a role as low as Contributor to perform SSRF attack.
6.1
CVE-2025-10357 - Simple SEO < 2.0.32 - Contributor+ Stored XSS
The Simple SEO WordPress plugin before 2.0.32 does not sanitise and escape some parameters when outputing them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.
4.3
CVE-2025-10732 - SureForms β Drag and Drop Form Builder for WordPress <= 1.12.1 - Missing Authorization to Authenticβ¦
The SureForms β Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.12.1. This is due to improper access control implementation on the '/wp-json/sureforms/v1/srfm-global-settings' REST API endpoint. β¦
8.6
CVE-2025-59889 -
Improper authentication of library files in the Eaton IPP software installer could lead to arbitrary code execution of an attacker with the access to the software package.Β This security issue has been fixed in the latest version of IPP which is available on the Eaton download center.
4.3
CVE-2025-42939 - Missing Authorization Check in SAP S/4HANA (Manage Processing Rules - For Bank Statements)
SAP S/4HANA (Manage Processing Rules - For Bank Statements) allows an authenticated attacker with basic privileges to delete conditions from any shared rule of any user by tampering the request parameter. Due to missing authorization check, the attacker can delete shared rule conditions that shouldβ¦
9.8
CVE-2025-42937 - Directory Traversal vulnerability in SAP Print Service
SAP Print Service (SAPSprint) performs insufficient validation of path information provided by users. An unauthenticated attacker could traverse to the parent directory and over-write system files causing high impact on confidentiality integrity and availability of the application.
9
CVE-2025-42910 - Unrestricted File Upload Vulnerability in SAP Supplier Relationship Management
Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attacker to upload arbitrary files. These files could include executables which might be downloaded and executed by the user which could host malware. On successful exploitation an attaβ¦
3
CVE-2025-42909 - Security Misconfiguration vulnerability in SAP Cloud Appliance Library Appliances
SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default profile setting in an existing SAP CAL appliances to gain access to other appliances. This has low impact on confidentiality of the application, integrity and availability is not iβ¦
5.4
CVE-2025-42908 - Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP
Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP, an authenticated attacker could initiate transactions directly via the session manager, bypassing the first transaction screen and the associated authorization check. This vulnerability could alloβ¦
5.3
CVE-2025-42906 - Directory Traversal vulnerability in SAP Commerce Cloud
SAP Commerce Cloud contains a path traversal vulnerability that may allow users to access web applications such as the Administration Console from addresses where the Administration Console is not explicitly deployed. This could potentially bypass configured access restrictions, resulting in a low β¦