2025 CVE Vulnerabilities

45,268 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-31325MEDIUM5.8Due to a Cross-Site Scripting vulnerability in SAP NetWeaver (ABAP Keyword Documentation), an unauthenticated attacker c...
CVE-2025-23192HIGH7.6SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store malicious...
CVE-2025-5905HIGH8.8A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been rated as critical. Affected by this issue is the fun...
CVE-2025-5904HIGH8.8A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. Affected by this vulnerability...
CVE-2025-5903HIGH8.8A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been classified as critical. Affected is the function set...
CVE-2025-0037MEDIUM6.6In AMD Versal Adaptive SoC devices, the lack of address validation when executing PLM runtime services through the PLM f...
CVE-2025-0036LOW3.2In AMD Versal Adaptive SoC devices, the incorrect configuration of the SSS during runtime (post-boot) cryptographic oper...
CVE-2025-5902HIGH8.8A vulnerability was found in TOTOLINK T10 4.1.8cu.5207 and classified as critical. This issue affects the function setUp...
CVE-2025-5901HIGH8.8A vulnerability has been found in TOTOLINK T10 4.1.8cu.5207 and classified as critical. This vulnerability affects the f...
CVE-2025-30515HIGH8.8CyberData 011209 Intercom could allow an authenticated attacker to upload arbitrary files to multiple locations within...
CVE-2025-30507HIGH7.5CyberData 011209 Intercom could allow an unauthenticated user to gather sensitive information through blind SQL injectio...
CVE-2025-30183HIGH8.7CyberData 011209 Intercom does not properly store or protect web server admin credentials.
CVE-2025-26468HIGH8.7CyberData  011209 Intercom exposes features that could allow an unauthenticated to gain access and cause a denial-of...
CVE-2025-5900HIGH7.1A vulnerability, which was classified as problematic, was found in Tenda AC9 15.03.02.13. This affects an unknown part. ...
CVE-2025-5899MEDIUM5.3A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected by this ...
CVE-2025-5898MEDIUM5.3A vulnerability classified as critical has been found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected is ...
CVE-2025-49140HIGH7.5Pion Interceptor is a framework for building RTP/RTCP communication software. Versions v0.1.36 through v0.1.38 contain a...
CVE-2025-30184CRITICAL9.8CyberData 011209 Intercom could allow an unauthenticated user access to the Web Interface through an alternate path.
CVE-2025-5897HIGH7.5A vulnerability was found in vuejs vue-cli up to 5.0.8. It has been rated as problematic. This issue affects the functio...
CVE-2025-5896HIGH7.5A vulnerability was found in tarojs taro up to 4.1.1. It has been declared as problematic. This vulnerability affects un...
CVE-2025-49141HIGH8.8HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.3, the `gitImportS...
CVE-2025-49139MEDIUM6.5HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, in the HAX site...
CVE-2025-49138MEDIUM6.5HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, an authenticate...
CVE-2025-49137MEDIUM6.1HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, the application...
CVE-2025-49004HIGH7.5Caido is a web security auditing toolkit. Prior to version 0.48.0, due to the lack of protection for DNS rebinding, Caid...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now