2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-49341HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Alex Furr PDF Creator Lite pdf-creator-lite allows Stored XSS.This is...
CVE-2025-42878HIGH8.2SAP Web Dispatcher and ICM may expose internal testing interfaces that are not intended for production. If enabled, unau...
CVE-2025-42877HIGH7.5SAP Web Dispatcher, Internet Communication Manager (ICM), and SAP Content Server allow an unauthenticated user to exploi...
CVE-2025-42876HIGH7.1Due to a Missing Authorization Check vulnerability in SAP S/4 HANA Private Cloud (Financials General Ledger), an authent...
CVE-2025-42874HIGH7.9SAP NetWeaver remote service for Xcelsius allows an attacker with network access and high privileges to execute arbitrar...
CVE-2025-41752HIGH7.1An XSS vulnerability in pxc_portSfp.php can be used by an unauthenticated remote attacker to trick an authenticated user...
CVE-2025-41751HIGH7.1An XSS vulnerability in pxc_portCntr.php can be used by an unauthenticated remote attacker to trick an authenticated use...
CVE-2025-41750HIGH7.1An XSS vulnerability in pxc_PortCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user...
CVE-2025-41749HIGH7.1An XSS vulnerability in port_util.php can be used by an unauthenticated remote attacker to trick an authenticated user t...
CVE-2025-41748HIGH7.1An XSS vulnerability in pxc_Dot1xCfg.php can be used by an unauthenticated remote attacker to trick an authenticated use...
CVE-2025-41747HIGH7.1An XSS vulnerability in pxc_vlanIntfCfg.php can be used by an unauthenticated remote attacker to trick an authenticated ...
CVE-2025-41746HIGH7.1An XSS vulnerability in pxc_portSecCfg.php can be used by an unauthenticated remote attacker to trick an authenticated u...
CVE-2025-41745HIGH7.1An XSS vulnerability in pxc_portCntr2.php can be used by an unauthenticated remote attacker to trick an authenticated us...
CVE-2025-41695HIGH7.1An XSS vulnerability in dyn_conn.php can be used by an unauthenticated remote attacker to trick an authenticated user to...
CVE-2025-40937HIGH8.8A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application do not properly...
CVE-2025-40831HIGH7.1A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application lacks i...
CVE-2025-40830HIGH8.4A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application does no...
CVE-2025-40820HIGH7.5Affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within ...
CVE-2025-40801HIGH8.1A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi...
CVE-2025-40800HIGH7.4A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), NX V2...
CVE-2025-40344HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: avs: Disable periods-elapsed work when...
CVE-2025-40342HIGH8.8In the Linux kernel, the following vulnerability has been resolved: nvme-fc: use lock accessing port_state and rport st...
CVE-2025-40337HIGH8.2In the Linux kernel, the following vulnerability has been resolved: net: stmmac: Correctly handle Rx checksum offload e...
CVE-2025-40336HIGH8.8In the Linux kernel, the following vulnerability has been resolved: drm/gpusvm: fix hmm_pfn_to_map_order() usage Handl...
CVE-2025-40334HIGH7.3In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate userq buffer virtual address a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now