8.6

CVSS3.1

CVE-2025-30018 - Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an application servlet request with a crafted XML file which when parsed, enables the attacker to access sensitive files and data. This vulnerability has a high impact on the applicat…

📅 Published: May 13, 2025, 12:16 a.m. 🔄 Last Modified: Oct. 23, 2025, 4:43 p.m.

10

CVSS3.1

CVE-2025-30012 - Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component, which allows an unauthenticated attacker to send malicious payload request in a specific encoding format. The servlet will then decode this malicious request which will result in deserial…

📅 Published: May 13, 2025, 12:14 a.m. 🔄 Last Modified: Oct. 23, 2025, 4:52 p.m.

5.3

CVSS3.1

CVE-2025-30011 - Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to send an malicious request to the application, which could disclose the internal version details of the affected…

📅 Published: May 13, 2025, 12:13 a.m. 🔄 Last Modified: Oct. 23, 2025, 4:55 p.m.

6.1

CVSS3.1

CVE-2025-30010 - Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to craft a malicious link, which when clicked by a victim, redirects the browser to a malicious site. On successfu…

📅 Published: May 13, 2025, 12:13 a.m. 🔄 Last Modified: Oct. 23, 2025, 4:57 p.m.

6.1

CVSS3.1

CVE-2025-30009 - Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)

he Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to execute malicious script in the victim�s browser. This vulnerability has low impact on confidentiality and integ…

📅 Published: May 13, 2025, 12:12 a.m. 🔄 Last Modified: Oct. 23, 2025, 5 p.m.

4.4

CVSS3.1

CVE-2025-26662 - Cross-Site Scripting (XSS) vulnerability in the SAP Data Services Management Console

The Data Services Management Console does not sufficiently encode user-controlled inputs, allowing an attacker to inject malicious script. When a targeted victim, who is already logged in, clicks on the compromised link, the injected script gets executed within the scope of victim�s browser. This p…

📅 Published: May 13, 2025, 12:09 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-56526 -

An issue was discovered in OXID eShop before 7. CMS pages in combination with Smarty may display user information if a CMS page contains a Smarty syntax error.

📅 Published: May 13, 2025, midnight 🔄 Last Modified: Jan. 29, 2026, 8:47 p.m.

10

CVSS3.1

CVE-2024-46506 -

NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because function=savesettings lacks an authentication requirement, as exploited in the wild in May 2025. This is related to settings.php and util.php.

📅 Published: May 13, 2025, midnight 🔄 Last Modified: June 17, 2025, 7:39 p.m.

5.4

CVSS3.1

CVE-2025-45864 -

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolStart parameter in the formDhcpv6s interface.

📅 Published: May 13, 2025, midnight 🔄 Last Modified: June 17, 2025, 7:41 p.m.

8.6

CVSS3.1

CVE-2024-48766 -

NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and because of factors related to strpos and directory traversal, as exploited in the wild in May 2025. This is related to components/logs.php.

📅 Published: May 13, 2025, midnight 🔄 Last Modified: June 24, 2025, 8:04 p.m.
Total resulsts: 346099
Page 5141 of 34,610
« previous page » next page
Filters