6.4

CVSS3.1

CVE-2025-6244 - Essential Addons for Elementor โ€“ Popular Elementor Templates and Widgets <= 6.1.19 - Authenticated โ€ฆ

The Essential Addons for Elementor โ€“ Popular Elementor Templates and Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the via `Calendar` And `Business Reviews` Widgets attributes in all versions up to, and including, 6.1.19 due to insufficient input sanitization and outโ€ฆ

๐Ÿ“… Published: July 8, 2025, 1:43 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:04 p.m.

5.3

CVSS4.0

CVE-2025-7156 - hitsz-ids airda completions execute sql injection

A vulnerability has been found in hitsz-ids airda 0.0.3 and classified as critical. This vulnerability affects the function execute of the file /v1/chat/completions. The manipulation of the argument question leads to sql injection. The attack can be initiated remotely. The exploit has been discloseโ€ฆ

๐Ÿ“… Published: July 8, 2025, 1:32 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-7146 - Jhenggao iPublish System - Arbitrary File Reading through Path Traversal

The iPublish System developed by Jhenggao has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to read arbitrary system file.

๐Ÿ“… Published: July 8, 2025, 1:19 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-7155 - PHPGurukul Online Notes Sharing System Cookie Dashboard sql injection

A vulnerability, which was classified as critical, was found in PHPGurukul Online Notes Sharing System 1.0. This affects an unknown part of the file /Dashboard of the component Cookie Handler. The manipulation of the argument sessionid leads to sql injection. It is possible to initiate the attack rโ€ฆ

๐Ÿ“… Published: July 8, 2025, 1:03 a.m. ๐Ÿ”„ Last Modified: July 13, 2025, 9:47 p.m.

6.9

CVSS3.1

CVE-2025-43001 - Multiple Privilege Escalation Vulnerabilities in SAPCAR

SAPCAR allows an attacker logged in with high privileges to override the permissions of the current and parent directories of the user or process extracting the archive, leading to privilege escalation. On successful exploitation, an attacker could modify the critical files by tampering with signedโ€ฆ

๐Ÿ“… Published: July 8, 2025, 12:38 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS3.1

CVE-2025-42992 - Multiple Privilege Escalation Vulnerabilities in SAPCAR

SAPCAR allows an attacker logged in with high privileges to create a malicious SAR archive in SAPCAR. This could enable the attacker to exploit critical files and directory permissions without breaking signature validation, resulting in potential privilege escalation. This has high impact on integrโ€ฆ

๐Ÿ“… Published: July 8, 2025, 12:38 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-42986 - Missing Authorization check in SAP NetWeaver and ABAP Platform

Due to a missing authorization check in an obsolete RFC enabled function module in SAP BASIS, an authenticated low-privileged attacker could call a Remote Function Call (RFC), potentially accessing restricted system information. This results in low impact on confidentiality, with no impact on integโ€ฆ

๐Ÿ“… Published: July 8, 2025, 12:38 a.m. ๐Ÿ”„ Last Modified: Oct. 27, 2025, 4:55 p.m.

6.1

CVSS3.1

CVE-2025-42985 - Open Redirect vulnerability in SAP BusinessObjects Content Administrator workbench

Due to insufficient sanitization in the SAP BusinessObjects Content Administrator Workbench, attackers could craft malicious URLs and execute scripts in a victim๏ฟฝs browser. This could potentially lead to the exposure or modification of web client data, resulting in low impact on confidentiality andโ€ฆ

๐Ÿ“… Published: July 8, 2025, 12:38 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-42981 - Multiple vulnerabilities in SAP NetWeaver Application Server ABAP

Due to an open redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft a URL link embedding a malicious script at a location not properly sanitized. When a victim clicks on this link, the script executes within the victim's browser, redirecting them โ€ฆ

๐Ÿ“… Published: July 8, 2025, 12:38 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-42980 - Insecure Deserialization in SAP NetWeaver Enterprise Portal Federated Portal Network

SAP NetWeaver Enterprise Portal Federated Portal Network is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.

๐Ÿ“… Published: July 8, 2025, 12:38 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345234
Page 4360 of 34,524
ยซ previous page ยป next page
Filters