Vulnerabilities (CVE)

Total 398387 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-30038 2026-06-17 N/A N/A
The vulnerability consists of a session ID leak when saving a file downloaded from CGM CLININET. The identifier is exposed through a built-in Windows security feature that stores additional metadata in an NTFS alternate data stream (ADS) for all files downloaded from potentially untrusted sources.
CVE-2025-30037 2026-06-17 N/A N/A
The system exposes several endpoints, typically including "/int/" in their path, that should be restricted to internal services, but are instead publicly accessible without authentication to any host able to reach the application server on port 443/tcp.
CVE-2025-30036 2026-06-17 N/A N/A
Stored XSS vulnerability exists in the "Oddział" (Ward) module, in the death diagnosis description field, and allows the execution of arbitrary JavaScript code. This can lead to session hijacking of other users and potentially to privilege escalation up to full administrative rights.
CVE-2025-30035 2026-06-17 N/A N/A
The vulnerability enables an attacker to fully bypass authentication in CGM CLININET and gain access to any active user account by supplying only the username, without requiring a password or any other credentials. Obtaining a session ID is sufficient for session takeover and grants access to the system with the privileges of the targeted user.
CVE-2025-30034 1 Siemens 1 Simatic Rtls Locating Manager 2026-06-17 N/A 6.2 MEDIUM
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3). Affected devices do not properly validate input sent to its listening port on the local loopback interface. This could allow an unauthenticated local attacker to cause a denial of service condition.
CVE-2025-30032 1 Siemens 1 Telecontrol Server Basic 2026-06-17 N/A 8.8 HIGH
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateDatabaseSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with "NT AUTHORITY\NetworkService" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on. (ZDI-CAN-25921)
CVE-2025-30031 1 Siemens 1 Telecontrol Server Basic 2026-06-17 N/A 8.8 HIGH
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateUsers' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with "NT AUTHORITY\NetworkService" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on. (ZDI-CAN-25922)
CVE-2025-30030 1 Siemens 1 Telecontrol Server Basic 2026-06-17 N/A 8.8 HIGH
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'ImportDatabase' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with "NT AUTHORITY\NetworkService" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on. (ZDI-CAN-25924)
CVE-2025-30028 1 Synology 2 Active Backup For Business, Diskstation Manager 2026-06-17 N/A 8.6 HIGH
A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files.
CVE-2025-30027 1 Axis 1 Axis Os 2026-06-17 N/A 6.7 MEDIUM
An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
CVE-2025-30026 1 Axis 2 Camera Station, Camera Station Pro 2026-06-17 N/A 9.8 CRITICAL
The AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally required.
CVE-2025-30025 1 Axis 2 Camera Station Pro, Device Manager 2026-06-17 N/A 7.8 HIGH
The communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalation.
CVE-2025-30024 1 Axis 1 Device Manager 2026-06-17 N/A 6.8 MEDIUM
The communication protocol used between client and server had a flaw that could be leveraged to execute a man in the middle attack.
CVE-2025-30023 1 Axis 3 Camera Station, Camera Station Pro, Device Manager 2026-06-17 N/A 9.0 CRITICAL
The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack.
CVE-2025-30022 1 Cmsol 1 Auto Atendimento 2026-06-17 N/A 6.8 MEDIUM
CM Soluces Informatica Ltda Auto Atendimento 1.x.x was discovered to contain a SQL injection via the DATANASC parameter.
CVE-2025-30018 1 Sap 1 Supplier Relationship Management 2026-06-17 N/A 8.6 HIGH
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an application servlet request with a crafted XML file which when parsed, enables the attacker to access sensitive files and data. This vulnerability has a high impact on the application's confidentiality, with no effect on integrity and availability of the application.
CVE-2025-30017 2026-06-17 N/A 4.4 MEDIUM
Due to a missing authorization check, an authenticated attacker could upload a file as a template for solution documentation in SAP Solution Manager 7.1. After successful exploitation, an attacker can cause limited impact on the integrity and availability of the application.
CVE-2025-30016 2026-06-17 N/A 9.8 CRITICAL
SAP Financial Consolidation allows an unauthenticated attacker to gain unauthorized access to the Admin account. The vulnerability arises due to improper authentication mechanisms, due to which there is high impact on the Confidentiality, Integrity & Availability of the application.
CVE-2025-30015 2026-06-17 N/A 4.1 MEDIUM
Due to incorrect memory address handling in ABAP SQL of SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker with high privileges could execute certain forms of SQL queries leading to manipulation of content in the output variable. This vulnerability has a low impact on the confidentiality, integrity and the availability of the application.
CVE-2025-30014 2026-06-17 N/A 7.7 HIGH
SAP Capital Yield Tax Management has directory traversal vulnerability due to insufficient path validation. This could allow an attacker with low privileges to read files from directory which they don�t have access to, hence causing a high impact on confidentiality. Integrity and Availability are not affected.