6.5

CVSS3.1

CVE-2025-42917 - Missing Authorization check in SAP HCM (Approve Timesheets Fiori 2.0 application)

SAP HCM Approve Timesheets Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This issue has a significant impact on the application's integrity, while confidentiality and availability remain unaffected.

๐Ÿ“… Published: Sept. 9, 2025, 2:09 a.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:49 p.m.

8.1

CVSS3.1

CVE-2025-42916 - Missing input validation vulnerability in SAP S/4HANA (Private Cloud or On-Premise)

Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables are not protected by an authorization group. This leads to a high impact on integrity and availability of the database but no impact on confidโ€ฆ

๐Ÿ“… Published: Sept. 9, 2025, 2:07 a.m. ๐Ÿ”„ Last Modified: Sept. 9, 2025, 9:31 p.m.

5.4

CVSS3.1

CVE-2025-42915 - Missing Authorization Check in Fiori app (Manage Payment Blocks)

Fiori app Manage Payment Blocks does not perform the necessary authorization checks, allowing an attacker with basic user privileges to abuse functionalities that should be restricted to specific user groups.This issue could impact both the confidentiality and integrity of the application without aโ€ฆ

๐Ÿ“… Published: Sept. 9, 2025, 2:06 a.m. ๐Ÿ”„ Last Modified: Sept. 9, 2025, 9:31 p.m.

3.1

CVSS3.1

CVE-2025-42914 - Missing Authorization check in SAP HCM (My Timesheet Fiori 2.0 application)

Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and perform activities that are otherwise restricted, resulting in a low impact on the integrity of the application. Confidentialityโ€ฆ

๐Ÿ“… Published: Sept. 9, 2025, 2:06 a.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:49 p.m.

3.1

CVSS3.1

CVE-2025-42913 - Missing Authorization check in SAP HCM (My Timesheet Fiori 2.0 application)

Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and perform activities that are otherwise restricted, resulting in a low impact on the integrity of the application. Confidentialityโ€ฆ

๐Ÿ“… Published: Sept. 9, 2025, 2:06 a.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:49 p.m.

6.5

CVSS3.1

CVE-2025-42912 - Missing Authorization check in SAP HCM (My Timesheet Fiori 2.0 application)

SAP HCM My Timesheet Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This issue has a significant impact on the application's integrity, while confidentiality and availability remain unaffected.

๐Ÿ“… Published: Sept. 9, 2025, 2:06 a.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:49 p.m.

5

CVSS3.1

CVE-2025-42911 - Missing Authorization check in SAP NetWeaver (Service Data Download)

SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled function module, which could grant access to information about the SAP system and operating system. This leads to a low impact on confidentiality, with no effect on the integrity and availability of the applโ€ฆ

๐Ÿ“… Published: Sept. 9, 2025, 2:05 a.m. ๐Ÿ”„ Last Modified: Oct. 23, 2025, 12:45 p.m.

5.3

CVSS4.0

CVE-2025-10121 - uverif kami_list addbatch sql injection

A flaw has been found in uverif up to 3.2. This affects the function addbatch of the file /admin/kami_list. This manipulation of the argument note causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.

๐Ÿ“… Published: Sept. 9, 2025, 2:02 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-10120 - Tenda AC20 GetParentControlInfo strcpy buffer overflow

A vulnerability was detected in Tenda AC20 up to 16.03.08.12. The impacted element is the function strcpy of the file /goform/GetParentControlInfo. The manipulation of the argument mac results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be used.

๐Ÿ“… Published: Sept. 9, 2025, 1:32 a.m. ๐Ÿ”„ Last Modified: Sept. 10, 2025, 4:41 p.m.

6.9

CVSS4.0

CVE-2025-10118 - itsourcecode E-Logbook with Health Monitoring System for COVID-19 login.php sql injection

A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotelโ€ฆ

๐Ÿ“… Published: Sept. 9, 2025, 1:32 a.m. ๐Ÿ”„ Last Modified: Sept. 10, 2025, 4:42 p.m.
Total resulsts: 349182
Page 3954 of 34,919
ยซ previous page ยป next page
Filters