6.9

CVSS4.0

CVE-2025-5906 - code-projects Laundry System data missing authentication

A vulnerability classified as critical has been found in code-projects Laundry System 1.0. This affects an unknown part of the file /data/. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

📅 Published: June 10, 2025, 12:31 a.m. 🔄 Last Modified: June 13, 2025, 7:51 p.m.

5.3

CVSS3.1

CVE-2025-42998 - Security misconfiguration vulnerability in SAP Business One Integration Framework

The security settings in the SAP Business One Integration Framework are not adequately checked, allowing attackers to bypass the 403 Forbidden error and access restricted pages. This leads to low impact on confidentiality of the application, there is no impact on integrity and availability.

📅 Published: June 10, 2025, 12:14 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.6

CVSS3.1

CVE-2025-42996 - Multiple vulnerabilities in SAP MDM Server

SAP MDM Server allows an attacker to gain control of existing client sessions and execute certain functions without having to re-authenticate giving the ability to access or modify non-sensitive information or consume sufficient resources which could degrade the performance of the server causing lo…

📅 Published: June 10, 2025, 12:13 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-42995 - Multiple vulnerabilities in SAP MDM Server

SAP MDM Server Read function allows an attacker to send specially crafted packets which could trigger a memory read access violation in the server process that would then fail and exit unexpectedly causing high impact on availability with no impact on confidentiality and integrity of the applicatio…

📅 Published: June 10, 2025, 12:13 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-42994 - Multiple vulnerabilities in SAP MDM Server

SAP MDM Server ReadString function allows an attacker to send specially crafted packets which could trigger a memory read access violation in the server process that would then fail and exit unexpectedly causing high impact on availability with no impact on confidentiality and integrity of the appl…

📅 Published: June 10, 2025, 12:13 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.7

CVSS3.1

CVE-2025-42993 - Missing Authorization Check in SAP S/4HANA (Enterprise Event Enablement)

Due to a missing authorization check vulnerability in SAP S/4HANA (Enterprise Event Enablement), an attacker with access to the Inbound Binding Configuration could create an RFC destination and assign an arbitrary high-privilege user. This allows the attacker to consume events via the RFC destinati…

📅 Published: June 10, 2025, 12:13 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-42991 - Missing Authorization check in SAP S/4HANA (Bank Account Application)

SAP S/4HANA (Bank Account Application) does not perform necessary authorization checks. This allows an authenticated 'approver' user to delete attachment from bank account application of other user, leading to a low impact on integrity, with no impact on the confidentiality of the data or the avail…

📅 Published: June 10, 2025, 12:12 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

3

CVSS3.1

CVE-2025-42990 - HTML Injection in Unprotected SAPUI5 applications

Unprotected SAPUI5 applications allow an attacker with basic privileges to inject malicious HTML code into a webpage, with the goal of redirecting users to the attacker controlled URL. This issue could impact the integrity of the application. Confidentiality or Availability are not impacted.

📅 Published: June 10, 2025, 12:12 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.6

CVSS3.1

CVE-2025-42989 - Missing Authorization check in SAP NetWeaver Application Server for ABAP

RFC inbound processing�does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation the attacker could critically impact both integrity and availability of the application.

📅 Published: June 10, 2025, 12:12 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

3.7

CVSS3.1

CVE-2025-42988 - Server-Side Request Forgery in SAP Business Objects Business Intelligence Platform

Under certain conditions, SAP Business Objects Business Intelligence Platform allows an unauthenticated attacker to enumerate HTTP endpoints in the internal network by specially crafting HTTP requests. This disclosure of information could further enable the researcher to cause SSRF. It has no impac…

📅 Published: June 10, 2025, 12:12 a.m. 🔄 Last Modified: Oct. 23, 2025, 2:26 p.m.
Total resulsts: 349182
Page 5102 of 34,919
« previous page » next page
Filters