Search
78,484 CVEs
CVEs (78,484, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 101–125 of 78,484 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2025-43774 | NONE | — | 2025-09-09 | Rejected reason: This CVE ID is rejected. The reported vulnerability was found to be present only in a feature that was under development and protected by a beta feature fl… | |
| CVE-2025-10116 | HIGH | 7.3 | 2025-09-09 | A vulnerability was identified in SiempreCMS up to 1.3.6. This vulnerability affects unknown code of the file /docs/admin/file_upload.php. Such manipulation leads to unrest… | |
| CVE-2025-10117 | LOW | 3.5 | 2025-09-09 | A weakness has been identified in SourceCodester Simple To-Do List System 1.0. Impacted is an unknown function of the file /fetch_tasks.php of the component Add New Task. E… | |
| CVE-2025-10118 | HIGH | 7.3 | 2025-09-09 | A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. The affected element is an unknown function of the file… | |
| CVE-2025-10120 | HIGH | Patched | 8.8 | 2025-09-09 | A vulnerability was detected in Tenda AC20 up to 16.03.08.12. The impacted element is the function strcpy of the file /goform/GetParentControlInfo. The manipulation of the … |
| CVE-2025-10121 | MEDIUM | 6.3 | 2025-09-09 | A flaw has been found in uverif up to 3.2. This affects the function addbatch of the file /admin/kami_list. This manipulation of the argument note causes sql injection. It … | |
| CVE-2025-42911 | MEDIUM | 5.0 | 2025-09-09 | SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled function module, which could grant access to information about the SAP system an… | |
| CVE-2025-42912 | MEDIUM | 6.5 | 2025-09-09 | SAP HCM My Timesheet Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This issue has … | |
| CVE-2025-42913 | LOW | 3.1 | 2025-09-09 | Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and p… | |
| CVE-2025-42914 | LOW | 3.1 | 2025-09-09 | Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and p… | |
| CVE-2025-42915 | MEDIUM | 5.4 | 2025-09-09 | Fiori app Manage Payment Blocks does not perform the necessary authorization checks, allowing an attacker with basic user privileges to abuse functionalities that should be… | |
| CVE-2025-42916 | HIGH | 8.1 | 2025-09-09 | Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables are not protect… | |
| CVE-2025-42917 | MEDIUM | 6.5 | 2025-09-09 | SAP HCM Approve Timesheets Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This issu… | |
| CVE-2025-42918 | MEDIUM | 4.3 | 2025-09-09 | SAP NetWeaver Application Server for ABAP allows authenticated users with access to background processing to gain unauthorized read access to profile parameters. This resu… | |
| CVE-2025-42920 | MEDIUM | 6.1 | 2025-09-09 | Due to a Cross-Site Scripting (XSS) vulnerability in the SAP Supplier Relationship Management, an unauthenticated attacker could generate a malicious link and make it publi… | |
| CVE-2025-42922 | CRITICAL | 9.9 | 2025-09-09 | SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw in an available service to upload an arbitrary file. This file when execut… | |
| CVE-2025-42923 | MEDIUM | 4.3 | 2025-09-09 | Due to insufficient CSRF protection in SAP Fiori App Manage Work Center Groups, an authenticated user could be tricked by an attacker to send unintended request to the web … | |
| CVE-2025-42925 | MEDIUM | 4.3 | 2025-09-09 | Due to the lack of randomness in assigning Object Identifiers in the SAP NetWeaver AS JAVA IIOP service, an authenticated attacker with low privileges could predict the ide… | |
| CVE-2025-42926 | MEDIUM | 5.3 | 2025-09-09 | SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files within the web application.Upon successful… | |
| CVE-2025-42927 | LOW | 3.4 | 2025-09-09 | SAP NetWeaver AS Java application uses Adobe Document Service, installed with a vulnerable version of OpenSSL.Successful exploitation of known vulnerabilities in the outdat… | |
| CVE-2025-42929 | HIGH | 8.1 | 2025-09-09 | Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables are not protect… | |
| CVE-2025-42930 | MEDIUM | 6.5 | 2025-09-09 | SAP Business Planning and Consolidation allows an authenticated standard user to call a function module by crafting specific parameters that causes a loop, consuming excess… | |
| CVE-2025-42933 | HIGH | 8.8 | 2025-09-09 | When a user logs in via SAP Business One native client, the SLD backend service fails to enforce proper encryption of certain APIs. This leads to exposure of sensitive cred… | |
| CVE-2025-42938 | MEDIUM | 6.1 | 2025-09-09 | Due to a Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly acces… | |
| CVE-2025-42944 | CRITICAL | 10.0 | 2025-09-09 | Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through the RMI-P4 module by submitting malicious payload to a… |