Return to the home page
105 new CVEs published on 2025-04-08 (CVSS: 7.3 - 10.0)

105 new CVEs published on 2025-04-08 (CVSS: 7.3 - 10.0)

CybersecurityVulnerabilitiesExploitsSoftwareSecurity

CVE IDCVSSDescription
CVE-2024-540929.8A vulnerability has been identified in Industrial Edge Device Kit - arm64 V1.17 (All versions), Industrial Edge Device Kit - arm64 V1.18 (All versions).
CVE-2025-20049.1The Simple WP Events plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wpe_delete_file AJAX function.
CVE-2024-417889.1A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions).

The web interface of affected devices does not sanitize the input.

CVE-2024-417899.1A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitize the language.
CVE-2024-417909.1A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions).

The web interface of affected devices does not sanitize the request.

CVE-2024-4179410.0A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). Affected devices contain hardcoded credentials for remote access.
CVE-2025-274299.9SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC.

This flaw enables the injection of arbitrary commands.

CVE-2025-313309.9SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary commands.
CVE-2025-300169.8SAP Financial Consolidation allows an unauthenticated attacker to gain unauthorized access to the Admin account.

The vulnerability arises due to improper access control.

CVE-2025-231868.5In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restrict access.
CVE-2025-274287.7Due to directory traversal vulnerability, an authorized attacker could gain access to some critical information by using RFC enabled function module.
CVE-2025-32489.8Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint.

A remote and unauthenticated attacker can send arbitrary code.

CVE-2025-33619.8The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands.
CVE-2025-290879.8Sqlite 3.49.0 is susceptible to integer overflow through the concat function.
CVE-2025-209468.8Improper handling of exceptional conditions in pairing specific Bluetooth devices in Galaxy Watch Bluetooth pairing prior to SMR Apr-2025 Release 1 allows attackers to exploit vulnerabilities.

ps://www.cyberhub.blog/cves/CVE-2025-3371" target="_blank" rel="noopener noreferrer">CVE-2025-3371

7.3A vulnerability has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the component.
CVE-2025-33727.3A vulnerability has been found in PCMan FTP Server 2.0.7. Affected is an unknown function of the component MKDIR Command.
CVE-2025-33737.3A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical.

Affected by this vulnerability is an unknown functionality of the component.

CVE-2025-33747.3A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown functionality of the component.