2025 CVE Vulnerabilities
45,260 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-42971 | MEDIUM | 4 | 0.1% | Jul 8, 2025 | A memory corruption vulnerability exists in SAPCAR allowing an attacker to craft malicious SAPCAR archives. When a high ... |
| CVE-2025-42970 | MEDIUM | 5.8 | 0.3% | Jul 8, 2025 | SAPCAR improperly sanitizes the file paths while extracting SAPCAR archives. Due to this, an attacker could craft a mali... |
| CVE-2025-42969 | MEDIUM | 6.1 | 0.2% | Jul 8, 2025 | SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject a malicious script ... |
| CVE-2025-42968 | MEDIUM | 4.3 | 0.2% | Jul 8, 2025 | SAP NetWeaver allows an authenticated non-administrative user to call the remote-enabled function module which could gra... |
| CVE-2025-42967 | CRITICAL | 9.9 | 0.9% | Jul 8, 2025 | SAP S/4HANA and SAP SCM Characteristic Propagation has remote code execution vulnerability. This allows an attacker with... |
| CVE-2025-42966 | CRITICAL | 9.1 | 0.7% | Jul 8, 2025 | SAP NetWeaver XML Data Archiving Service allows an authenticated attacker with administrative privileges to exploit an i... |
| CVE-2025-42965 | MEDIUM | 4.1 | 0.2% | Jul 8, 2025 | SAP CMC Promotion Management allows an authenticated attacker to enumerate internal network systems by submitting crafte... |
| CVE-2025-42964 | CRITICAL | 9.1 | 0.7% | Jul 8, 2025 | SAP NetWeaver Enterprise Portal Administration is vulnerable when a privileged user can upload untrusted or malicious co... |
| CVE-2025-42963 | CRITICAL | 9.1 | 0.7% | Jul 8, 2025 | A critical vulnerability in SAP NetWeaver Application server for Java Log Viewer enables authenticated administrator use... |
| CVE-2025-42962 | MEDIUM | 6.1 | 0.2% | Jul 8, 2025 | SAP Business Warehouse (Business Explorer Web) allows an attacker to create a malicious link. If an authenticated user c... |
| CVE-2025-42961 | MEDIUM | 4.9 | 0.3% | Jul 8, 2025 | Due to a missing authorization check in SAP NetWeaver Application server for ABAP, an authenticated user with high privi... |
| CVE-2025-42960 | MEDIUM | 4.3 | 0.2% | Jul 8, 2025 | SAP Business Warehouse and SAP BW/4HANA BEx Tools allow an authenticated attacker to gain higher access levels than inte... |
| CVE-2025-42959 | HIGH | 8.1 | 0.5% | Jul 8, 2025 | An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential, extract... |
| CVE-2025-42954 | LOW | 2.7 | 0.4% | Jul 8, 2025 | SAP NetWeaver Business Warehouse CCAW application allows a privileged attacker to cause a high CPU load by executing a R... |
| CVE-2025-42953 | HIGH | 8.1 | 0.4% | Jul 8, 2025 | SAP Netweaver System Configuration does not perform necessary authorization checks for an authenticated user, resulting ... |
| CVE-2025-42952 | HIGH | 7.7 | 0.4% | Jul 8, 2025 | SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to add fields to arbitrary SAP database ta... |
| CVE-2025-31326 | MEDIUM | 4.1 | 0.2% | Jul 8, 2025 | SAP�BusinessObjects Business�Intelligence Platform (Web Intelligence) is vulnerable to HTML Injection, allowing an attac... |
| CVE-2025-7153 | MEDIUM | 5.4 | 0.3% | Jul 8, 2025 | A vulnerability classified as problematic was found in CodeAstro Simple Hospital Management System 1.0. Affected by this... |
| CVE-2025-7152 | HIGH | 8.8 | 0.4% | Jul 8, 2025 | A vulnerability classified as critical has been found in Campcodes Advanced Online Voting System 1.0. Affected is an unk... |
| CVE-2025-7151 | HIGH | 8.8 | 0.4% | Jul 7, 2025 | A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been rated as critical. This issue affe... |
| CVE-2025-7150 | HIGH | 8.8 | 0.4% | Jul 7, 2025 | A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been declared as critical. This vulnera... |
| CVE-2025-7149 | HIGH | 8.8 | 0.4% | Jul 7, 2025 | A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been classified as critical. This affec... |
| CVE-2025-7148 | MEDIUM | 5.4 | 0.3% | Jul 7, 2025 | A vulnerability was found in CodeAstro Simple Hospital Management System 1.0 and classified as problematic. Affected by ... |
| CVE-2025-7147 | CRITICAL | 9.8 | 0.5% | Jul 7, 2025 | A vulnerability has been found in CodeAstro Patient Record Management System 1.0 and classified as critical. Affected by... |
| CVE-2025-7144 | MEDIUM | 4.8 | 0.3% | Jul 7, 2025 | A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as problematic. This vu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now