Total
397457 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-23196 | 1 Apache | 1 Ambari | 2026-06-17 | N/A | 8.8 HIGH |
| A code injection vulnerability exists in the Ambari Alert Definition feature, allowing authenticated users to inject and execute arbitrary shell commands. The vulnerability arises when defining alert scripts, where the script filename field is executed using `sh -c`. An attacker with authenticated access can exploit this vulnerability to inject malicious commands, leading to remote code execution on the server. The issue has been fixed in the latest versions of Ambari. | |||||
| CVE-2025-23195 | 1 Apache | 1 Ambari | 2026-06-17 | N/A | 7.5 HIGH |
| An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie project, allowing an attacker to inject malicious XML entities. This vulnerability occurs due to insecure parsing of XML input using the `DocumentBuilderFactory` class without disabling external entity resolution. An attacker can exploit this vulnerability to read arbitrary files on the server or perform server-side request forgery (SSRF) attacks. The issue has been fixed in both Ambari 2.7.9 and the trunk branch. | |||||
| CVE-2025-23194 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| SAP NetWeaver Enterprise Portal OBN does not perform proper authentication check for a particular configuration setting. As result, a non-authenticated user can set it to an undesired value causing low impact on integrity. There is no impact on confidentiality or availability of the application. | |||||
| CVE-2025-23193 | 1 Sap | 1 Sap Basis | 2026-06-17 | N/A | 5.3 MEDIUM |
| SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respond differently based on the existence of a specified user, potentially revealing sensitive information. This issue does not enable data modification and has no impact on server availability. | |||||
| CVE-2025-23192 | 1 Sap | 1 Businessobjects Business Intelligence | 2026-06-17 | N/A | 8.2 HIGH |
| SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store malicious script within a workspace. When the victim accesses the workspace, the script will execute in their browser enabling the attacker to potentially access sensitive session information, modify or make browser information unavailable. This leads to a high impact on confidentiality and low impact on integrity, availability. | |||||
| CVE-2025-23191 | 2026-06-17 | N/A | 3.1 LOW | ||
| Cached values belonging to the SAP OData endpoint in SAP Fiori for SAP ERP could be poisoned by modifying the Host header value in an HTTP GET request. An attacker could alter the `atom:link` values in the returned metadata redirecting them from the SAP server to a malicious link set by the attacker. Successful exploitation could cause low impact on integrity of the application. | |||||
| CVE-2025-23190 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Due to missing authorization check, an authenticated attacker could call a remote-enabled function module which allows them to access data that they would otherwise not have access to. The attacker cannot modify data or impact the availability of the system. | |||||
| CVE-2025-23189 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an authenticated attacker could generate technical meta-data. This leads to a low impact on integrity. There is no impact on confidentiality or availability | |||||
| CVE-2025-23188 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| An authenticated user with low privileges can exploit a missing authorization check in an IBS module of FS-RBD, allowing unauthorized access to perform actions beyond their intended permissions. This causes a low impact on integrity with no impact on confidentiality and availability. | |||||
| CVE-2025-23187 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an unauthenticated attacker could generate technical meta-data. This leads to a low impact on integrity. There is no impact on confidentiality or availability. | |||||
| CVE-2025-23186 | 2026-06-17 | N/A | 8.5 HIGH | ||
| In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, which can be used to expose credentials for a remote service. These credentials can then be further exploited to completely compromise the remote service, potentially resulting in a significant impact on the confidentiality, integrity, and availability of the application. | |||||
| CVE-2025-23185 | 2026-06-17 | N/A | 4.1 MEDIUM | ||
| Due to improper error handling in SAP Business Objects Business Intelligence Platform, technical details of the application are revealed in exceptions thrown to the user and in stack traces. Only an attacker with administrator level privileges has access to this disclosed information, and they could use it to craft further exploits. There is no impact on the integrity and availability of the application. | |||||
| CVE-2025-23184 | 1 Apache | 1 Cxf | 2026-06-17 | N/A | 5.9 MEDIUM |
| A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients). | |||||
| CVE-2025-23183 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| CWE-601: URL Redirection to Untrusted Site ('Open Redirect') | |||||
| CVE-2025-23182 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| CWE-203: Observable Discrepancy | |||||
| CVE-2025-23181 | 2026-06-17 | N/A | 8.0 HIGH | ||
| CWE-250: Execution with Unnecessary Privileges | |||||
| CVE-2025-23180 | 2026-06-17 | N/A | 8.0 HIGH | ||
| CWE-250: Execution with Unnecessary Privileges | |||||
| CVE-2025-23179 | 2026-06-17 | N/A | 5.5 MEDIUM | ||
| CWE-798: Use of Hard-coded Credentials | |||||
| CVE-2025-23178 | 2026-06-17 | N/A | 7.6 HIGH | ||
| CWE-923: Improper Restriction of Communication Channel to Intended Endpoints | |||||
| CVE-2025-23177 | 2026-06-17 | N/A | 7.6 HIGH | ||
| CWE-427: Uncontrolled Search Path Element | |||||
