CVE-2025-42903Medium· 4.3▾ SunlitA vulnerability in SAP Financial Service Claims Management RFC function ICL_USER_GET_NAME_AND_ADDRESS allows user enumeration and potential disclosure of personal data through response discrepancies, causing low impact on confidentiality…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
A vulnerability in SAP Financial Service Claims Management RFC function ICL_USER_GET_NAME_AND_ADDRESS allows user enumeration and potential disclosure of personal data through response discrepancies, causing low impact on confidentiality with no impact on integrity or availability.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-62236Medium· 5.3The Frontier Airlines website has a publicly available endpoint that validates if an email addresses is associated with an account
CVE-2025-34155NoneTibbo AggreGate Network Manager < 6.40.05 contains an observable response discrepancy in its login functionality
CVE-2025-67874Medium· 6.5ChurchCRM is an open-source church management system
CVE-2025-40806Medium· 5.3A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1)
CVE-2018-25350Critical· 9.8userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by sending POST requests to the existingUsernameCheck.php endpoint
CVE-2026-59785Medium· 5.1Host search in Frontend allows filtering by fields that are not displayed, including stored IPMI and PSK credentials