6.8

CVSS3.1

CVE-2025-37088 -

A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on race conditions and configuration, this vulnerability may lead to local/cluster unauthorized access.

πŸ“… Published: April 22, 2025, 9:55 p.m. πŸ”„ Last Modified: April 25, 2025, 3:15 p.m.

5.5

CVSS3.1

CVE-2025-27087 -

A vulnerability in the kernel of the Cray Operating System (COS) could allow an attacker to perform a local Denial of Service (DoS) attack.

πŸ“… Published: April 22, 2025, 9:38 p.m. πŸ”„ Last Modified: April 23, 2025, 2:15 p.m.

9.8

CVSS3.1

CVE-2025-37087 -

A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access to an arbitrary file on the server host.

πŸ“… Published: April 22, 2025, 8:58 p.m. πŸ”„ Last Modified: May 7, 2025, 7:43 p.m.

9.3

CVSS4.0

CVE-2025-32965 - Compromised xrpl.js versions 4.2.1, 4.2.2, 4.2.3, 4.2.4, and 2.14.2

xrpl.js is a JavaScript/TypeScript API for interacting with the XRP Ledger in Node.js and the browser. Versions 4.2.1, 4.2.2, 4.2.3, and 4.2.4 of xrpl.js were compromised and contained malicious code designed to exfiltrate private keys. Version 2.14.2 is also malicious, though it is less likely to …

πŸ“… Published: April 22, 2025, 8:39 p.m. πŸ”„ Last Modified: April 23, 2025, 2:08 p.m.

2.5

CVSS3.1

CVE-2025-23253 -

NVIDIA NvContainer service for Windows contains a vulnerability in its usage of OpenSSL, where an attacker could exploit a hard-coded constant issue by copying a malicious DLL in a hard-coded path. A successful exploit of this vulnerability might lead to code execution, denial of service, escalatio…

πŸ“… Published: April 22, 2025, 6:45 p.m. πŸ”„ Last Modified: April 23, 2025, 2:08 p.m.

4.6

CVSS3.1

CVE-2025-31328 - Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4 HANA (Learning Solution)

SAP Learning Solution is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to trick authenticated user into sending unintended requests to the server. GET-based OData function is named in a way that it violates the expected behaviour. This issue could impact both the confidentia…

πŸ“… Published: April 22, 2025, 6:25 p.m. πŸ”„ Last Modified: April 23, 2025, 3:58 p.m.

4.3

CVSS3.1

CVE-2025-31327 - OData meta-data property entity tampering in SAP Field Logistics

SAP Field Logistics Manage Logistics application OData meta-data property is vulnerable to data tampering, due to which certain fields could be externally modified by an attacker causing low impact on integrity of the application. Confidentiality and availability are not impacted.

πŸ“… Published: April 22, 2025, 6:25 p.m. πŸ”„ Last Modified: April 23, 2025, 3:58 p.m.

6.4

CVSS3.1

CVE-2025-32961 - CUBA JPA Web API Vulnerable to Cross-Site Scripting (XSS) in the /download Endpoint

The Cuba JPA web API enables loading and saving any entities defined in the application data model by sending simple HTTP requests. Prior to version 1.1.1, the input parameter, which consists of a file path and name, can be manipulated to return the Content-Type header with text/html if the name pa…

πŸ“… Published: April 22, 2025, 5:46 p.m. πŸ”„ Last Modified: April 23, 2025, 3:59 p.m.

6.4

CVSS3.1

CVE-2025-32960 - CUBA Generic REST API Vulnerable to Cross-Site Scripting (XSS) in the /files Endpoint

The CUBA REST API add-on performs operations on data and entities. Prior to version 7.2.7, the input parameter, which consists of a file path and name, can be manipulated to return the Content-Type header with text/html if the name part ends with .html. This could allow malicious JavaScript code to…

πŸ“… Published: April 22, 2025, 5:45 p.m. πŸ”„ Last Modified: April 23, 2025, 3:59 p.m.

6.5

CVSS3.1

CVE-2025-32959 - CUBA Vulnerable to Denial of Service (DoS) in the File Storage

CUBA Platform is a high level framework for enterprise applications development. Prior to version 7.2.23, the local file storage implementation does not restrict the size of uploaded files. An attacker could exploit this by uploading excessively large files, potentially causing the server to run ou…

πŸ“… Published: April 22, 2025, 5:45 p.m. πŸ”„ Last Modified: April 23, 2025, 2:08 p.m.
Total resulsts: 344045
Page 5180 of 34,405
Β« previous page Β» next page
Filters