2025 CVE Vulnerabilities

45,268 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-5925MEDIUM4.3The Bunny’s Print CSS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2025-5913CRITICAL9.8A vulnerability was found in PHPGurukul Vehicle Record Management System 1.0. It has been rated as critical. This issue ...
CVE-2025-5912HIGH8.8A vulnerability was found in D-Link DIR-632 FW103B08. It has been declared as critical. This vulnerability affects the f...
CVE-2025-4601HIGH8.8The "RH - Real Estate WordPress Theme" theme for WordPress is vulnerable to Privilege Escalation in all versions up to, ...
CVE-2025-4387HIGH8.8The Abandoned Cart Pro for WooCommerce plugin contains an authenticated arbitrary file upload vulnerability due to missi...
CVE-2025-5911HIGH8.8A vulnerability was found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713 and classified as critical. Affected by this ...
CVE-2025-5910HIGH8.8A vulnerability has been found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713 and classified as critical. Affected by ...
CVE-2025-5909HIGH8.8A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713. Affected ...
CVE-2025-5908HIGH8.8A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713. This...
CVE-2025-5907HIGH8.8A vulnerability classified as critical was found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713. This vulnerability af...
CVE-2025-5906CRITICAL9.8A vulnerability classified as critical has been found in code-projects Laundry System 1.0. This affects an unknown part ...
CVE-2025-42998MEDIUM5.3The security settings in the SAP Business One Integration Framework are not adequately checked, allowing attackers to by...
CVE-2025-42996MEDIUM5.6SAP MDM Server allows an attacker to gain control of existing client sessions and execute certain functions without havi...
CVE-2025-42995HIGH7.5SAP MDM Server Read function allows an attacker to send specially crafted packets which could trigger a memory read acce...
CVE-2025-42994HIGH7.5SAP MDM Server ReadString function allows an attacker to send specially crafted packets which could trigger a memory rea...
CVE-2025-42993MEDIUM6.7Due to a missing authorization check vulnerability in SAP S/4HANA (Enterprise Event Enablement), an attacker with access...
CVE-2025-42991MEDIUM4.3SAP S/4HANA (Bank Account Application) does not perform necessary authorization checks. This allows an authenticated 'ap...
CVE-2025-42990LOW3Unprotected SAPUI5 applications allow an attacker with basic privileges to inject malicious HTML code into a webpage, wi...
CVE-2025-42989CRITICAL9.6RFC inbound processing�does not perform necessary authorization checks for an authenticated user, resulting in escalatio...
CVE-2025-42988MEDIUM5.3Under certain conditions, SAP Business Objects Business Intelligence Platform allows an unauthenticated attacker to enum...
CVE-2025-42987MEDIUM4.3SAP Manage Processing Rules (For Bank Statement) allows an attacker with basic privileges to edit shared rules of any us...
CVE-2025-42984MEDIUM5.4SAP S/4HANA Manage Central Purchase Contract does not perform necessary authorization checks for an authenticated user. ...
CVE-2025-42983HIGH8.5SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to drop arbitrary SAP database tables, pot...
CVE-2025-42982HIGH8.8SAP GRC allows a non-administrative user to access and initiate transaction which could allow them to modify or control ...
CVE-2025-42977HIGH7.6SAP NetWeaver Visual Composer contains a Directory Traversal vulnerability caused by insufficient validation of input pa...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now