3.1

CVSS3.1

CVE-2025-11731 - Libxslt: type confusion in exsltfuncresultcompfunction of libxslt

A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during stylesheet parsing. Due to improper type handling, the function may treat an XML document node as a regular XML element node, resulting in a type confusion. This can cause unexpected…

πŸ“… Published: Oct. 14, 2025, 6:02 a.m. πŸ”„ Last Modified: Oct. 14, 2025, 6:02 a.m.

0.0

CVE-2025-8594 - Pz-LinkCard < 2.5.7 - Contributor+ SSRF

The Pz-LinkCard WordPress plugin before 2.5.7 does not validate a parameter before making a request to it, which could allow users with a role as low as Contributor to perform SSRF attack.

πŸ“… Published: Oct. 14, 2025, 6 a.m. πŸ”„ Last Modified: Oct. 14, 2025, 6 a.m.

0.0

CVE-2025-10357 - Simple SEO < 2.0.32 - Contributor+ Stored XSS

The Simple SEO WordPress plugin before 2.0.32 does not sanitise and escape some parameters when outputing them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.

πŸ“… Published: Oct. 14, 2025, 6 a.m. πŸ”„ Last Modified: Oct. 14, 2025, 6 a.m.

4.3

CVSS3.1

CVE-2025-10732 - SureForms – Drag and Drop Form Builder for WordPress <= 1.12.1 - Missing Authorization to Authentic…

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.12.1. This is due to improper access control implementation on the '/wp-json/sureforms/v1/srfm-global-settings' REST API endpoint. …

πŸ“… Published: Oct. 14, 2025, 5:24 a.m. πŸ”„ Last Modified: Oct. 14, 2025, 5:24 a.m.

8.6

CVSS3.1

CVE-2025-59889 -

Improper authentication of library files in the Eaton IPP software installer could lead to arbitrary code execution of an attacker with the access to the software package.

πŸ“… Published: Oct. 14, 2025, 5:11 a.m. πŸ”„ Last Modified: Oct. 14, 2025, 5:11 a.m.

4.3

CVSS3.1

CVE-2025-42939 - Missing Authorization Check in SAP S/4HANA (Manage Processing Rules - For Bank Statements)

SAP S/4HANA (Manage Processing Rules - For Bank Statements) allows an authenticated attacker with basic privileges to delete conditions from any shared rule of any user by tampering the request parameter. Due to missing authorization check, the attacker can delete shared rule conditions that should…

πŸ“… Published: Oct. 14, 2025, 12:18 a.m. πŸ”„ Last Modified: Oct. 14, 2025, 12:18 a.m.

9.8

CVSS3.1

CVE-2025-42937 - Directory Traversal vulnerability in SAP Print Service

SAP Print Service (SAPSprint) performs insufficient validation of path information provided by users. An unauthenticated attacker could traverse to the parent directory and over-write system files causing high impact on confidentiality integrity and availability of the application.

πŸ“… Published: Oct. 14, 2025, 12:18 a.m. πŸ”„ Last Modified: Oct. 14, 2025, 12:18 a.m.

9

CVSS3.1

CVE-2025-42910 - Unrestricted File Upload Vulnerability in SAP Supplier Relationship Management

Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attacker to upload arbitrary files. These files could include executables which might be downloaded and executed by the user which could host malware. On successful exploitation an atta…

πŸ“… Published: Oct. 14, 2025, 12:18 a.m. πŸ”„ Last Modified: Oct. 14, 2025, 12:18 a.m.

3

CVSS3.1

CVE-2025-42909 - Security Misconfiguration vulnerability in SAP Cloud Appliance Library Appliances

SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default profile setting in an existing SAP CAL appliances to gain access to other appliances. This has low impact on confidentiality of the application, integrity and availability is not i…

πŸ“… Published: Oct. 14, 2025, 12:18 a.m. πŸ”„ Last Modified: Oct. 14, 2025, 12:18 a.m.

5.4

CVSS3.1

CVE-2025-42908 - Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP

Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP, an authenticated attacker could initiate transactions directly via the session manager, bypassing the first transaction screen and the associated authorization check. This vulnerability could allo…

πŸ“… Published: Oct. 14, 2025, 12:18 a.m. πŸ”„ Last Modified: Oct. 14, 2025, 12:18 a.m.
Total resulsts: 314311
Page 43 of 31,432
Β« previous page Β» next page
Filters