Latest CVE Feed
-
9.9
CRITICALCVE-2025-42950
SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks.... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
-
4.9
MEDIUMCVE-2025-42949
Due to a missing authorization check in the ABAP Platform, an authenticated user with elevated privileges could bypass authorization restrictions for common transactions by leveraging the SQL Console. This could enable an attacker to access and read the c... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
-
4.5
MEDIUMCVE-2025-42943
SAP GUI for Windows may allow the leak of NTML hashes when specific ABAP frontend services are called with UNC paths. For a successful attack, the attacker needs developer authorization in a specific Application Server ABAP to make changes in the code, an... Read more
Affected Products : gui_for_windows- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
-
3.5
LOWCVE-2025-42941
SAP Fiori (Launchpad) is vulnerable to Reverse Tabnabbing vulnerability due to inadequate external navigation protections for its link (<a>) elements. An attacker with administrative user privileges could exploit this by leveraging compromised or maliciou... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
-
5.1
MEDIUMCVE-2025-55159
slab is a pre-allocated storage for a uniform data type. In version 0.4.10, the get_disjoint_mut method incorrectly checked if indices were within the slab's capacity instead of its length, allowing access to uninitialized memory. This could lead to undef... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 12, 2025
-
6.9
MEDIUMCVE-2025-54992
OpenKilda is an open-source OpenFlow controller. Prior to version 1.164.0, an XML external entity (XXE) injection vulnerability was found in OpenKilda which in combination with GHSL-2025-024 allows unauthenticated attackers to exfiltrate information from ... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 12, 2025
-
8.6
HIGHCVE-2025-54878
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. A heap buffer overflow v... Read more
Affected Products : cryptolib- Published: Aug. 11, 2025
- Modified: Aug. 12, 2025
-
9.8
CRITICALCVE-2024-32640
MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.6, 7.3.13, and 7.2.8 contain a SQL injection vulnerability in the `processAsyncObject` method that can result in remote code execution. Versions 7... Read more
Affected Products : masacms- Published: Aug. 11, 2025
- Modified: Aug. 12, 2025
-
7.5
HIGHCVE-2025-54525
Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to create channel subscription endpoint with an invalid request body.... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 12, 2025
-
5.0
MEDIUMCVE-2025-54458
Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscription for a Confluence space the user does not have access to via the create subscription endpoint.... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 12, 2025
-
3.7
LOWCVE-2025-53857
Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the GET autocomplete/GetChannelSubscriptions e... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 12, 2025
-
3.7
LOWCVE-2025-49221
Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to access subscription details without via API call to GET subscription endpoint.... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 12, 2025
-
7.2
HIGHCVE-2025-44004
Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance which allows attackers to create a channel subscription without proper authorization via API call to the create channel subscription endpoi... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 12, 2025
-
5.4
MEDIUMCVE-2025-25229
Omnissa Workspace ONE UEM contains a Server-Side Request Forgery (SSRF) Vulnerability. A malicious actor with user privileges may be able to access restricted internal system information, potentially enabling enumeration of internal network resources.... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 12, 2025
-
6.1
MEDIUMCVE-2025-42942
SAP NetWeaver Application Server for ABAP has cross-site scripting vulnerability. Due to this, an unauthenticated attacker could craft a URL embedded with malicious script and trick an unauthenticated victim to click on it to execute the script. Upon succ... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
-
5.4
MEDIUMCVE-2025-42936
The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations for different user roles, this issue allows authenticated users to access restricted objects in the barcode interface, leading to privile... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
-
9.8
CRITICALCVE-2025-30184
CyberData 011209 Intercom could allow an unauthenticated user access to the Web Interface through an alternate path.... Read more
- Published: Jun. 09, 2025
- Modified: Aug. 12, 2025
-
7.5
HIGHCVE-2025-30507
CyberData 011209 Intercom could allow an unauthenticated user to gather sensitive information through blind SQL injections.... Read more
- Published: Jun. 09, 2025
- Modified: Aug. 12, 2025
-
9.8
CRITICALCVE-2025-30515
CyberData 011209 Intercom could allow an authenticated attacker to upload arbitrary files to multiple locations within the system.... Read more
- Published: Jun. 09, 2025
- Modified: Aug. 12, 2025
-
8.7
HIGHCVE-2025-30183
CyberData 011209 Intercom does not properly store or protect web server admin credentials.... Read more
- Published: Jun. 09, 2025
- Modified: Aug. 12, 2025