CVE Database

52637+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-43001
6.9 MEDIUM

SAPCAR allows an attacker logged in with high privileges to override the permissions of the current and parent directories of the user or process extracting …

Jul 8, 2025
CVE-2025-42992
6.9 MEDIUM

SAPCAR allows an attacker logged in with high privileges to create a malicious SAR archive in SAPCAR. This could enable the attacker to exploit critical …

Jul 8, 2025
CVE-2025-42986
4.3 MEDIUM

Due to a missing authorization check in an obsolete RFC enabled function module in SAP BASIS, an authenticated low-privileged attacker could call a Remote Function …

Jul 8, 2025
CVE-2025-42985
6.1 MEDIUM

Due to insufficient sanitization in the SAP BusinessObjects Content Administrator Workbench, attackers could craft malicious URLs and execute scripts in a victim�s browser. This could …

Jul 8, 2025
CVE-2025-42981
6.1 MEDIUM

Due to an open redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft a URL link embedding a malicious script at …

Jul 8, 2025
CVE-2025-42979
5.6 MEDIUM

The GuiXT application, which is integrated with SAP GUI for Windows, uses obfuscation algorithms instead of secure symmetric ciphers for storing the credentials of an …

Jul 8, 2025
CVE-2025-42974
4.3 MEDIUM

Due to missing authorization check, an attacker authenticated as a non-administrative user could call a remote-enabled function module. This could enable access to information normally …

Jul 8, 2025
CVE-2025-42973
5.4 MEDIUM

Due to a Cross-Site Scripting vulnerability in SAP Data Services Management Console, an authenticated attacker could exploit the search functionality associated with DQ job status …

Jul 8, 2025
CVE-2025-42971
4.0 MEDIUM

A memory corruption vulnerability exists in SAPCAR allowing an attacker to craft malicious SAPCAR archives. When a high privileged victim extracts this malicious archive, it …

Jul 8, 2025
CVE-2025-42970
5.8 MEDIUM

SAPCAR improperly sanitizes the file paths while extracting SAPCAR archives. Due to this, an attacker could craft a malicious SAPCAR archive containing directory traversal sequences. …

Jul 8, 2025
CVE-2025-42969
6.1 MEDIUM

SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject a malicious script into a dynamically crafted URL. The victim, when …

Jul 8, 2025
CVE-2025-42968
5.0 MEDIUM

SAP NetWeaver allows an authenticated non-administrative user to call the remote-enabled function module which could grants access to non-sensitive information about the SAP system and …

Jul 8, 2025
CVE-2025-42965
4.1 MEDIUM

SAP CMC Promotion Management allows an authenticated attacker to enumerate internal network systems by submitting crafted requests during job source configuration. By analysing response times …

Jul 8, 2025
CVE-2025-42962
6.1 MEDIUM

SAP Business Warehouse (Business Explorer Web) allows an attacker to create a malicious link. If an authenticated user clicks on this link, the injected script …

Jul 8, 2025
CVE-2025-42961
4.9 MEDIUM

Due to a missing authorization check in SAP NetWeaver Application server for ABAP, an authenticated user with high privileges could exploit the insufficient validation of …

Jul 8, 2025
CVE-2025-42960
4.3 MEDIUM

SAP Business Warehouse and SAP BW/4HANA BEx Tools allow an authenticated attacker to gain higher access levels than intended by exploiting improper authorization checks. This …

Jul 8, 2025
CVE-2025-31326
4.1 MEDIUM

SAP�BusinessObjects Business�Intelligence Platform (Web Intelligence) is vulnerable to HTML Injection, allowing an attacker with basic user privileges to inject malicious code into specific input fields. …

Jul 8, 2025
CVE-2025-7152
6.3 MEDIUM

A vulnerability classified as critical has been found in Campcodes Advanced Online Voting System 1.0. Affected is an unknown function of the file /admin/candidates_add.php. The …

Jul 8, 2025
CVE-2025-7151
6.3 MEDIUM

A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Jul 7, 2025
CVE-2025-7150
6.3 MEDIUM

A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Jul 7, 2025
CVE-2025-7149
6.3 MEDIUM

A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been classified as critical. This affects an unknown part of the file …

Jul 7, 2025
CVE-2025-53543
4.2 MEDIUM

Kestra is an event-driven orchestration platform. The error message in execution "Overview" tab is vulnerable to stored XSS due to improper handling of HTTP response …

Jul 7, 2025
CVE-2025-53496
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MediaSearch Extension allows Stored XSS.This issue affects …

Jul 7, 2025
CVE-2025-6044
6.1 MEDIUM

An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices allows a physical attacker to …

Jul 7, 2025
CVE-2025-53498
5.3 MEDIUM

Insufficient Logging vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Data Leakage Attacks.This issue affects Mediawiki - AbuseFilter Extension: from 1.43.X before 1.43.2.

Jul 7, 2025
CVE-2025-53488
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - WikiHiero Extension allows Stored XSS.This issue affects …

Jul 7, 2025
CVE-2025-53478
5.4 MEDIUM

The CheckUser extension’s Special:Investigate interface is vulnerable to reflected XSS due to improper escaping of certain internationalized system messages rendered on the “IPs and User …

Jul 7, 2025
CVE-2025-7138
6.3 MEDIUM

A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Jul 7, 2025
CVE-2025-20324
5.4 MEDIUM

In Splunk Enterprise versions below 9.4.2, 9.3.5, 9.2.7, and 9.1.10 and Splunk Cloud Platform versions below 9.3.2411.104, 9.3.2408.113, and 9.2.2406.119, a low-privileged user that does …

Jul 7, 2025
CVE-2025-20323
4.3 MEDIUM

In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a low-privileged user that does not hold the "admin" or "power" Splunk roles could turn …

Jul 7, 2025
CVE-2025-20322
4.3 MEDIUM

In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.104, 9.3.2408.113, and 9.2.2406.119, an unauthenticated attacker could send …

Jul 7, 2025
CVE-2025-20321
6.5 MEDIUM

In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7 and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.104, 9.3.2408.114, and 9.2.2406.119, an unauthenticated attacker can send …

Jul 7, 2025
CVE-2025-20320
6.3 MEDIUM

In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7 and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.107, 9.3.2408.117, and 9.2.2406.121, a low-privileged user that does …

Jul 7, 2025
CVE-2025-20319
6.8 MEDIUM

In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a user who holds a role that contains the high-privilege capability `edit_scripted` and `list_inputs` capability …

Jul 7, 2025
CVE-2025-20300
4.3 MEDIUM

In Splunk Enterprise versions below 9.4.2, 9.3.5, 9.2.6, and 9.1.9 and Splunk Cloud Platform versions below 9.3.2411.103, 9.3.2408.112, and 9.2.2406.119, a low-privileged user that does …

Jul 7, 2025
CVE-2024-43190
5.9 MEDIUM

IBM Engineering Requirements Management DOORS 9.7.2.9, under certain configurations, could allow a remote attacker to obtain password reset instructions of a legitimate user using man …

Jul 7, 2025
CVE-2024-37658
6.1 MEDIUM

An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the bbs/member_confirm.php.

Jul 7, 2025
CVE-2024-37657
6.1 MEDIUM

An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via thebbs/login.php component.

Jul 7, 2025
CVE-2024-37656
6.1 MEDIUM

An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the insufficient URL parameter verification in bbs/logout.php.

Jul 7, 2025
CVE-2025-7137
6.3 MEDIUM

A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

Jul 7, 2025
CVE-2025-53532
5.3 MEDIUM

giscus is a commenting system powered by GitHub Discussions. A bug in giscus' discussions creation API allowed an unauthorized user to create discussions on any …

Jul 7, 2025
CVE-2025-53526
6.1 MEDIUM

WeGIA is a web manager for charitable institutions. An XSS Injection vulnerability was identified in novo_memorando.php. After the memo was submitted, the vulnerability was confirmed …

Jul 7, 2025
CVE-2025-53525
6.1 MEDIUM

WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the profile_familiar.php endpoint of the WeGIA application. This …

Jul 7, 2025
CVE-2025-53497
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - RelatedArticles Extension allows Stored XSS.This issue affects …

Jul 7, 2025
CVE-2025-53491
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - FlaggedRevs Extension allows Cross-Site Scripting (XSS).This issue …

Jul 7, 2025
CVE-2025-53377
6.1 MEDIUM

WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the cadastro_dependente_pessoa_nova.php endpoint of the WeGIA application. This …

Jul 7, 2025
CVE-2025-1351
6.7 MEDIUM

IBM Storage Virtualize 8.5, 8.6, and 8.7 products could allow a user to escalate their privileges to that of another user logging in at the …

Jul 7, 2025
CVE-2025-7259
6.5 MEDIUM

An authorized user can issue queries with duplicate _id fields, that leads to unexpected behavior in MongoDB Server, which may result to crash. This issue …

Jul 7, 2025
CVE-2025-7057
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Quiz Extension allows Stored XSS.This issue affects …

Jul 7, 2025
CVE-2025-53487
5.4 MEDIUM

The ApprovedRevs extension for MediaWiki is vulnerable to stored XSS in multiple locations where system messages are inserted into raw HTML without proper escaping. Attackers …

Jul 7, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.