6.1

CVSS3.1

CVE-2025-24867 - Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence platform (BI โ€ฆ

SAP BusinessObjects Platform (BI Launchpad) does not sufficiently handle user input, resulting in Cross-Site Scripting (XSS) vulnerability. The application allows an unauthenticated attacker to craft a URL that embeds a malicious script within an unprotected parameter. When a victim clicks the linkโ€ฆ

๐Ÿ“… Published: Feb. 11, 2025, 12:35 a.m. ๐Ÿ”„ Last Modified: Feb. 11, 2025, 3:58 p.m.

5.3

CVSS3.1

CVE-2025-23193 - Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP

SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respond differently based on the existence of a specified user, potentially revealing sensitive information. This issue does not enable data modification and has no impact on server avaโ€ฆ

๐Ÿ“… Published: Feb. 11, 2025, 12:35 a.m. ๐Ÿ”„ Last Modified: Oct. 23, 2025, 6:37 p.m.

3.1

CVSS3.1

CVE-2025-23191 - Cache Poisoning through header manipulation vulnerability in SAP Fiori for SAP ERP

Cached values belonging to the SAP OData endpoint in SAP Fiori for SAP ERP could be poisoned by modifying the Host header value in an HTTP GET request. An attacker could alter the `atom:link` values in the returned metadata redirecting them from the SAP server to a malicious link set by the attackeโ€ฆ

๐Ÿ“… Published: Feb. 11, 2025, 12:35 a.m. ๐Ÿ”„ Last Modified: Feb. 11, 2025, 4:01 p.m.

4.3

CVSS3.1

CVE-2025-23190 - Missing Authorization check in SAP NetWeaver and ABAP platform (ST-PI)

Due to missing authorization check, an authenticated attacker could call a remote-enabled function module which allows them to access data that they would otherwise not have access to. The attacker cannot modify data or impact the availability of the system.

๐Ÿ“… Published: Feb. 11, 2025, 12:35 a.m. ๐Ÿ”„ Last Modified: Feb. 11, 2025, 4:01 p.m.

4.3

CVSS3.1

CVE-2025-23189 - Missing Authorization Check in SAP NetWeaver and ABAP Platform (SDCCN)

Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an authenticated attacker could generate technical meta-data. This leads to a low impact on integrity. There is no impact on confidentiality or availability

๐Ÿ“… Published: Feb. 11, 2025, 12:33 a.m. ๐Ÿ”„ Last Modified: Feb. 11, 2025, 3:18 p.m.

5.3

CVSS3.1

CVE-2025-23187 - Missing Authorization Check in SAP NetWeaver and ABAP Platform (SDCCN)

Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an unauthenticated attacker could generate technical meta-data. This leads to a low impact on integrity. There is no impact on confidentiality or availability.

๐Ÿ“… Published: Feb. 11, 2025, 12:33 a.m. ๐Ÿ”„ Last Modified: Feb. 18, 2025, 6:15 p.m.

8.7

CVSS3.1

CVE-2025-0064 - Improper Authorization in SAP BusinessObjects Business Intelligence platform (Central Management Coโ€ฆ

Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intelligence platform allows an attacker with admin rights to generate or retrieve a secret passphrase, enabling them to impersonate any user in the system. This results in a high impact on confidentialityโ€ฆ

๐Ÿ“… Published: Feb. 11, 2025, 12:33 a.m. ๐Ÿ”„ Last Modified: Oct. 23, 2025, 6:41 p.m.

5.4

CVSS3.1

CVE-2025-0054 - Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java

SAP NetWeaver Application Server Java does not sufficiently handle user input, resulting in a stored cross-site scripting vulnerability. The application allows attackers with basic user privileges to store a Javascript payload on the server, which could be later executed in the victim's web browserโ€ฆ

๐Ÿ“… Published: Feb. 11, 2025, 12:32 a.m. ๐Ÿ”„ Last Modified: Feb. 18, 2025, 6:15 p.m.

6.9

CVSS4.0

CVE-2025-1165 - Lumsoft ERP FileUploadApi.ashx DoWebUpload unrestricted upload

A vulnerability, which was classified as critical, was found in Lumsoft ERP 8. Affected is the function DoUpload/DoWebUpload of the file /Api/FileUploadApi.ashx. The manipulation of the argument file leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been diโ€ฆ

๐Ÿ“… Published: Feb. 11, 2025, 12:31 a.m. ๐Ÿ”„ Last Modified: Feb. 18, 2025, 6:15 p.m.

4.8

CVSS4.0

CVE-2025-1164 - code-projects Police FIR Record Management System Add Record stack-based overflow

A vulnerability, which was classified as problematic, has been found in code-projects Police FIR Record Management System 1.0. This issue affects some unknown processing of the component Add Record Handler. The manipulation leads to stack-based buffer overflow. Local access is required to approach โ€ฆ

๐Ÿ“… Published: Feb. 11, 2025, midnight ๐Ÿ”„ Last Modified: April 11, 2025, 6:33 p.m.
Total resulsts: 343920
Page 6276 of 34,392
ยซ previous page ยป next page
Filters