6.4
CVE-2025-6244 - Essential Addons for Elementor โ Popular Elementor Templates and Widgets <= 6.1.19 - Authenticated โฆ
The Essential Addons for Elementor โ Popular Elementor Templates and Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the via `Calendar` And `Business Reviews` Widgets attributes in all versions up to, and including, 6.1.19 due to insufficient input sanitization and outโฆ
5.3
CVE-2025-7156 - hitsz-ids airda completions execute sql injection
A vulnerability has been found in hitsz-ids airda 0.0.3 and classified as critical. This vulnerability affects the function execute of the file /v1/chat/completions. The manipulation of the argument question leads to sql injection. The attack can be initiated remotely. The exploit has been discloseโฆ
8.7
CVE-2025-7146 - Jhenggao iPublish System - Arbitrary File Reading through Path Traversal
The iPublish System developed by Jhenggao has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to read arbitrary system file.
6.9
CVE-2025-7155 - PHPGurukul Online Notes Sharing System Cookie Dashboard sql injection
A vulnerability, which was classified as critical, was found in PHPGurukul Online Notes Sharing System 1.0. This affects an unknown part of the file /Dashboard of the component Cookie Handler. The manipulation of the argument sessionid leads to sql injection. It is possible to initiate the attack rโฆ
6.9
CVE-2025-43001 - Multiple Privilege Escalation Vulnerabilities in SAPCAR
SAPCAR allows an attacker logged in with high privileges to override the permissions of the current and parent directories of the user or process extracting the archive, leading to privilege escalation. On successful exploitation, an attacker could modify the critical files by tampering with signedโฆ
6.9
CVE-2025-42992 - Multiple Privilege Escalation Vulnerabilities in SAPCAR
SAPCAR allows an attacker logged in with high privileges to create a malicious SAR archive in SAPCAR. This could enable the attacker to exploit critical files and directory permissions without breaking signature validation, resulting in potential privilege escalation. This has high impact on integrโฆ
4.3
CVE-2025-42986 - Missing Authorization check in SAP NetWeaver and ABAP Platform
Due to a missing authorization check in an obsolete RFC enabled function module in SAP BASIS, an authenticated low-privileged attacker could call a Remote Function Call (RFC), potentially accessing restricted system information. This results in low impact on confidentiality, with no impact on integโฆ
6.1
CVE-2025-42985 - Open Redirect vulnerability in SAP BusinessObjects Content Administrator workbench
Due to insufficient sanitization in the SAP BusinessObjects Content Administrator Workbench, attackers could craft malicious URLs and execute scripts in a victim๏ฟฝs browser. This could potentially lead to the exposure or modification of web client data, resulting in low impact on confidentiality andโฆ
6.1
CVE-2025-42981 - Multiple vulnerabilities in SAP NetWeaver Application Server ABAP
Due to an open redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft a URL link embedding a malicious script at a location not properly sanitized. When a victim clicks on this link, the script executes within the victim's browser, redirecting them โฆ
9.1
CVE-2025-42980 - Insecure Deserialization in SAP NetWeaver Enterprise Portal Federated Portal Network
SAP NetWeaver Enterprise Portal Federated Portal Network is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.