Latest CVE Feed
-
6.4
MEDIUMCVE-2025-8568
The GMap Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘h’ parameter in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attac... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
-
6.4
MEDIUMCVE-2025-8462
The RT Easy Builder – Advanced addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the social URL parameter in all versions up to, and including, 2.3 due to insufficient input sanitization and output escaping. This m... Read more
Affected Products : rt_easy_builder- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
-
5.3
MEDIUMCVE-2025-4390
The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the 'validate_restrictions' function. This makes it possible for unauthenticated attackers to extract sensitiv... Read more
Affected Products : wp_private_content_plus- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
-
6.4
MEDIUMCVE-2025-8621
The Mosaic Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘c’ parameter in all versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
-
6.4
MEDIUMCVE-2025-8688
The Inline Stock Quotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's stock shortcode in all versions up to, and including, 0.2 due to insufficient input sanitization and output escaping on user supplied attributes. Th... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
-
6.9
MEDIUMCVE-2025-42946
Due to directory traversal vulnerability in SAP S/4HANA (Bank Communication Management), an attacker with high privileges and access to a specific transaction and method in Bank Communication Management could gain unauthorized access to sensitive operatin... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
-
8.1
HIGHCVE-2025-5391
The WooCommerce Purchase Orders plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_file() function in all versions up to, and including, 1.0.2. This makes it possible for authenticated atta... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
-
8.2
HIGHCVE-2025-7677
Missing Authentication for Critical Function vulnerability in ABB Aspect.This issue affects Aspect: All versions.... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 12, 2025
-
8.9
HIGHCVE-2025-7679
Missing Authentication for Critical Function vulnerability in ABB Aspect.This issue affects Aspect: All versions.... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 12, 2025
-
7.2
HIGHCVE-2025-54478
Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to edit channel subscriptions via API call to the edit channel subscription endpoint.... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 12, 2025
-
5.9
MEDIUMCVE-2025-54463
Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an invalid request body.... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 12, 2025
-
4.0
MEDIUMCVE-2025-8285
Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create channel subscription without proper access to the channel via API call to the create channel subscription endpoint.... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 12, 2025
-
8.6
HIGHCVE-2025-40920
Catalyst::Authentication::Credential::HTTP versions 1.018 and earlier for Perl generate nonces using the Perl Data::UUID library. * Data::UUID does not use a strong cryptographic source for generating UUIDs. * Data::UUID returns v3 UUIDs, which are g... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 12, 2025
-
8.6
HIGHCVE-2025-25235
Server-Side Request Forgery (SSRF) in Omnissa Secure Email Gateway (SEG) in SEG prior to 2.32 running on Windows and SEG prior to 2503 running on UAG allows routing of network traffic such as HTTP requests to internal networks.... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 12, 2025
-
8.5
HIGHCVE-2025-55012
Zed is a multiplayer code editor. Prior to version 0.197.3, in the Zed Agent Panel allowed for an AI agent to achieve Remote Code Execution (RCE) by bypassing user permission checks. An AI Agent could have exploited a permissions bypass vulnerability to c... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 12, 2025
-
4.1
MEDIUMCVE-2025-42935
The SAP NetWeaver Application Server ABAP and ABAP Platform Internet Communication Manager (ICM) permits authorized users with admin privileges and local access to log files to read sensitive information, resulting in information disclosure. This leads to... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
-
6.1
MEDIUMCVE-2025-42945
SAP NetWeaver Application Server ABAP has HTML injection vulnerability. Due to this, an attacker could craft a URL with malicious script as payload and trick a victim with active user session into executing it. Upon successful exploit, this vulnerability ... Read more
Affected Products : netweaver_application_server_abap- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
-
6.1
MEDIUMCVE-2025-42948
Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is processed du... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
-
8.8
HIGHCVE-2025-42951
Due to broken authorization, SAP Business One (SLD) allows an authenticated attacker to gain administrator privileges of a database by invoking the corresponding API.�As a result , it has a high impact on the confidentiality, integrity, and availability o... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
-
8.1
HIGHCVE-2025-42976
SAP NetWeaver Application Server ABAP (BIC Document) allows an authenticated attacker to craft a request that, when submitted to a BIC Document application, could cause a memory corruption error. On successful exploitation, this results in the crash of th... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025