2025 CVE Vulnerabilities

45,260 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-20690MEDIUM5.5In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local inf...
CVE-2025-20689MEDIUM5.5In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local inf...
CVE-2025-20688MEDIUM5.5In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local inf...
CVE-2025-20687MEDIUM5.5In Bluetooth driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local d...
CVE-2025-20686HIGH8.8In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (...
CVE-2025-20685HIGH8.8In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (...
CVE-2025-20684CRITICAL9.8In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es...
CVE-2025-20683CRITICAL9.8In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es...
CVE-2025-20682CRITICAL9.8In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es...
CVE-2025-20681CRITICAL9.8In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es...
CVE-2025-20680CRITICAL9.8In Bluetooth driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local ...
CVE-2025-7156MEDIUM6.3A vulnerability has been found in hitsz-ids airda 0.0.3 and classified as critical. This vulnerability affects the funct...
CVE-2025-7146HIGH8.7The iPublish System developed by Jhenggao has an Arbitrary File Reading vulnerability, allowing unauthenticated remote a...
CVE-2025-7155CRITICAL9.8A vulnerability, which was classified as critical, was found in PHPGurukul Online Notes Sharing System 1.0. This affects...
CVE-2025-7154HIGH8.8A vulnerability, which was classified as critical, has been found in TOTOLINK N200RE 9.3.5u.6095_B20200916/9.3.5u.6139_B...
CVE-2025-43001MEDIUM6.9SAPCAR allows an attacker logged in with high privileges to override the permissions of the current and parent directori...
CVE-2025-42992MEDIUM6.9SAPCAR allows an attacker logged in with high privileges to create a malicious SAR archive in SAPCAR. This could enable ...
CVE-2025-42986MEDIUM4.3Due to a missing authorization check in an obsolete RFC enabled function module in SAP BASIS, an authenticated low-privi...
CVE-2025-42985MEDIUM6.1Due to insufficient sanitization in the SAP BusinessObjects Content Administrator Workbench, attackers could craft malic...
CVE-2025-42981MEDIUM6.1Due to an open redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft ...
CVE-2025-42980CRITICAL9.1SAP NetWeaver Enterprise Portal Federated Portal Network is vulnerable when a privileged user can upload untrusted or ma...
CVE-2025-42979MEDIUM5.6The GuiXT application, which is integrated with SAP GUI for Windows, uses obfuscation algorithms instead of secure symme...
CVE-2025-42978LOW3.5The widely used component that establishes outbound TLS connections in SAP NetWeaver Application Server Java does not re...
CVE-2025-42974MEDIUM4.3Due to missing authorization check, an attacker authenticated as a non-administrative user could call a remote-enabled f...
CVE-2025-42973MEDIUM5.4Due to a Cross-Site Scripting vulnerability in SAP Data Services Management Console, an authenticated attacker could exp...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now