Medium - CVE-2025-42981 - Due to an open redirect vulnerability in SAP...
Due to an open redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft a URL link embedding a malicious script at a location not properly sanitized....
Medium - CVE-2025-42985 - Due to insufficient sanitization in the SAP...
Due to insufficient sanitization in the SAP BusinessObjects Content Administrator Workbench, attackers could craft malicious URLs and execute scripts in a victim?s browser. This could potentially...
Medium - CVE-2025-42986 - Due to a missing authorization check in an...
Due to a missing authorization check in an obsolete RFC enabled function module in SAP BASIS, an authenticated low-privileged attacker could call a Remote Function Call (RFC), potentially accessing...
Medium - CVE-2025-42992 - SAPCAR allows an attacker logged in with high...
SAPCAR allows an attacker logged in with high privileges to create a malicious SAR archive in SAPCAR. This could enable the attacker to exploit critical files and directory permissions without...
Medium - CVE-2025-43001 - SAPCAR allows an attacker logged in with high...
SAPCAR allows an attacker logged in with high privileges to override the permissions of the current and parent directories of the user or process extracting the archive, leading to privilege...
Medium - CVE-2025-7154 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, has been found in TOTOLINK N200RE 9.3.5u.6095_B20200916/9.3.5u.6139_B20201216. Affected by this issue is the function sub_41A0F8 of the file...
High - CVE-2025-7155 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, was found in PHPGurukul Online Notes Sharing System 1.0. This affects an unknown part of the file /Dashboard of the component Cookie Handler. The...
High - CVE-2025-7146 - The iPublish System developed by Jhenggao has...
The iPublish System developed by Jhenggao has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to read arbitrary system file.
Medium - CVE-2025-7156 - A vulnerability has been found in hitsz-ids...
A vulnerability has been found in hitsz-ids airda 0.0.3 and classified as critical. This vulnerability affects the function execute of the file /v1/chat/completions. The manipulation of the...
NA - CVE-2025-20680 - In Bluetooth driver, there is a possible out of...
In Bluetooth driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User...