9.4

CVSS4.0

CVE-2024-41790 -

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitize the region parameter in specific POST requests. This could allow an authenticated remote attacker to execute arbitrary code with root privileges.

πŸ“… Published: April 8, 2025, 8:22 a.m. πŸ”„ Last Modified: Sept. 23, 2025, 4:35 p.m.

9.4

CVSS4.0

CVE-2024-41789 -

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitize the language parameter in specific POST requests. This could allow an authenticated remote attacker to execute arbitrary code with root privileges.

πŸ“… Published: April 8, 2025, 8:22 a.m. πŸ”„ Last Modified: Sept. 23, 2025, 4:37 p.m.

9.4

CVSS4.0

CVE-2024-41788 -

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitize the input parameters in specific GET requests. This could allow an authenticated remote attacker to execute arbitrary code with root privileges.

πŸ“… Published: April 8, 2025, 8:22 a.m. πŸ”„ Last Modified: Sept. 23, 2025, 4:38 p.m.

5.3

CVSS3.1

CVE-2025-2882 - GreenPay(tm) by Green.Money 3.0.0 - 3.0.9 - Unauthenticated Information Exposure

The GreenPay(tm) by Green.Money plugin for WordPress is vulnerable to Sensitive Information Exposure in versions between 3.0.0 and 3.0.9 through the publicly accessible phpinfo.php script. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in th…

πŸ“… Published: April 8, 2025, 7:29 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-3431 - ZoomSounds - WordPress Wave Audio Player with Playlist <= 6.91 - Unauthenticated Arbitrary File Dow…

The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.91 via the 'dzsap_download' action. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server…

πŸ“… Published: April 8, 2025, 7:29 a.m. πŸ”„ Last Modified: April 20, 2026, 11:30 p.m.

4.3

CVSS3.1

CVE-2025-31333 - Odata meta-data tampering in SAP S4CORE entity

SAP S4CORE OData meta-data property is vulnerable to data tampering, due to which entity set could be externally modified by an attacker causing low impact on integrity of the application. Confidentiality and availability is not impacted.

πŸ“… Published: April 8, 2025, 7:15 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.6

CVSS3.1

CVE-2025-31332 - Insecure File permissions vulnerability in SAP BusinessObjects Business Intelligence Platform

Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker who has local access to the system could modify files potentially disrupting operations or cause service downtime hence leading to a high impact on integrity and availability. However, this vulnerabi…

πŸ“… Published: April 8, 2025, 7:15 a.m. πŸ”„ Last Modified: Oct. 24, 2025, 6:08 p.m.

4.3

CVSS3.1

CVE-2025-31331 - Authorization Bypass vulnerability in SAP NetWeaver

SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would normally require additional validation. Once logged into the ABAP system, the attacker can run a specific transaction that exposes sensitive system code without proper authorizati…

πŸ“… Published: April 8, 2025, 7:15 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.9

CVSS3.1

CVE-2025-31330 - Code Injection Vulnerability in SAP Landscape Transformation (Analysis Platform)

SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as…

πŸ“… Published: April 8, 2025, 7:15 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.4

CVSS3.1

CVE-2025-30017 - Missing Authorization check in SAP Solution Manager

Due to a missing authorization check, an authenticated attacker could upload a file as a template for solution documentation in SAP Solution Manager 7.1. After successful exploitation, an attacker can cause limited impact on the integrity and availability of the application.

πŸ“… Published: April 8, 2025, 7:15 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346087
Page 5663 of 34,609
Β« previous page Β» next page
Filters