2025 CVE Vulnerabilities

45,260 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-42971MEDIUM4A memory corruption vulnerability exists in SAPCAR allowing an attacker to craft malicious SAPCAR archives. When a high ...
CVE-2025-42970MEDIUM5.8SAPCAR improperly sanitizes the file paths while extracting SAPCAR archives. Due to this, an attacker could craft a mali...
CVE-2025-42969MEDIUM6.1SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject a malicious script ...
CVE-2025-42968MEDIUM4.3SAP NetWeaver allows an authenticated non-administrative user to call the remote-enabled function module which could gra...
CVE-2025-42967CRITICAL9.9SAP S/4HANA and SAP SCM Characteristic Propagation has remote code execution vulnerability. This allows an attacker with...
CVE-2025-42966CRITICAL9.1SAP NetWeaver XML Data Archiving Service allows an authenticated attacker with administrative privileges to exploit an i...
CVE-2025-42965MEDIUM4.1SAP CMC Promotion Management allows an authenticated attacker to enumerate internal network systems by submitting crafte...
CVE-2025-42964CRITICAL9.1SAP NetWeaver Enterprise Portal Administration is vulnerable when a privileged user can upload untrusted or malicious co...
CVE-2025-42963CRITICAL9.1A critical vulnerability in SAP NetWeaver Application server for Java Log Viewer enables authenticated administrator use...
CVE-2025-42962MEDIUM6.1SAP Business Warehouse (Business Explorer Web) allows an attacker to create a malicious link. If an authenticated user c...
CVE-2025-42961MEDIUM4.9Due to a missing authorization check in SAP NetWeaver Application server for ABAP, an authenticated user with high privi...
CVE-2025-42960MEDIUM4.3SAP Business Warehouse and SAP BW/4HANA BEx Tools allow an authenticated attacker to gain higher access levels than inte...
CVE-2025-42959HIGH8.1An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential, extract...
CVE-2025-42954LOW2.7SAP NetWeaver Business Warehouse CCAW application allows a privileged attacker to cause a high CPU load by executing a R...
CVE-2025-42953HIGH8.1SAP Netweaver System Configuration does not perform necessary authorization checks for an authenticated user, resulting ...
CVE-2025-42952HIGH7.7SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to add fields to arbitrary SAP database ta...
CVE-2025-31326MEDIUM4.1SAP�BusinessObjects Business�Intelligence Platform (Web Intelligence) is vulnerable to HTML Injection, allowing an attac...
CVE-2025-7153MEDIUM5.4A vulnerability classified as problematic was found in CodeAstro Simple Hospital Management System 1.0. Affected by this...
CVE-2025-7152HIGH8.8A vulnerability classified as critical has been found in Campcodes Advanced Online Voting System 1.0. Affected is an unk...
CVE-2025-7151HIGH8.8A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been rated as critical. This issue affe...
CVE-2025-7150HIGH8.8A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been declared as critical. This vulnera...
CVE-2025-7149HIGH8.8A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been classified as critical. This affec...
CVE-2025-7148MEDIUM5.4A vulnerability was found in CodeAstro Simple Hospital Management System 1.0 and classified as problematic. Affected by ...
CVE-2025-7147CRITICAL9.8A vulnerability has been found in CodeAstro Patient Record Management System 1.0 and classified as critical. Affected by...
CVE-2025-7144MEDIUM4.8A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as problematic. This vu...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now