2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49341 | HIGH | 7.1 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Alex Furr PDF Creator Lite pdf-creator-lite allows Stored XSS.This is... |
| CVE-2025-42878 | HIGH | 8.2 | 0.3% | Dec 9, 2025 | SAP Web Dispatcher and ICM may expose internal testing interfaces that are not intended for production. If enabled, unau... |
| CVE-2025-42877 | HIGH | 7.5 | 0.5% | Dec 9, 2025 | SAP Web Dispatcher, Internet Communication Manager (ICM), and SAP Content Server allow an unauthenticated user to exploi... |
| CVE-2025-42876 | HIGH | 7.1 | 0.3% | Dec 9, 2025 | Due to a Missing Authorization Check vulnerability in SAP S/4 HANA Private Cloud (Financials General Ledger), an authent... |
| CVE-2025-42874 | HIGH | 7.9 | 0.5% | Dec 9, 2025 | SAP NetWeaver remote service for Xcelsius allows an attacker with network access and high privileges to execute arbitrar... |
| CVE-2025-41752 | HIGH | 7.1 | 9.8% | Dec 9, 2025 | An XSS vulnerability in pxc_portSfp.php can be used by an unauthenticated remote attacker to trick an authenticated user... |
| CVE-2025-41751 | HIGH | 7.1 | 9.8% | Dec 9, 2025 | An XSS vulnerability in pxc_portCntr.php can be used by an unauthenticated remote attacker to trick an authenticated use... |
| CVE-2025-41750 | HIGH | 7.1 | 9.8% | Dec 9, 2025 | An XSS vulnerability in pxc_PortCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user... |
| CVE-2025-41749 | HIGH | 7.1 | 0.7% | Dec 9, 2025 | An XSS vulnerability in port_util.php can be used by an unauthenticated remote attacker to trick an authenticated user t... |
| CVE-2025-41748 | HIGH | 7.1 | 9.8% | Dec 9, 2025 | An XSS vulnerability in pxc_Dot1xCfg.php can be used by an unauthenticated remote attacker to trick an authenticated use... |
| CVE-2025-41747 | HIGH | 7.1 | 9.8% | Dec 9, 2025 | An XSS vulnerability in pxc_vlanIntfCfg.php can be used by an unauthenticated remote attacker to trick an authenticated ... |
| CVE-2025-41746 | HIGH | 7.1 | 9.8% | Dec 9, 2025 | An XSS vulnerability in pxc_portSecCfg.php can be used by an unauthenticated remote attacker to trick an authenticated u... |
| CVE-2025-41745 | HIGH | 7.1 | 0.7% | Dec 9, 2025 | An XSS vulnerability in pxc_portCntr2.php can be used by an unauthenticated remote attacker to trick an authenticated us... |
| CVE-2025-41695 | HIGH | 7.1 | 0.7% | Dec 9, 2025 | An XSS vulnerability in dyn_conn.php can be used by an unauthenticated remote attacker to trick an authenticated user to... |
| CVE-2025-40937 | HIGH | 8.8 | 0.5% | Dec 9, 2025 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application do not properly... |
| CVE-2025-40831 | HIGH | 7.1 | 0.3% | Dec 9, 2025 | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application lacks i... |
| CVE-2025-40830 | HIGH | 8.4 | 0.1% | Dec 9, 2025 | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application does no... |
| CVE-2025-40820 | HIGH | 7.5 | 0.5% | Dec 9, 2025 | Affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within ... |
| CVE-2025-40801 | HIGH | 8.1 | 0.3% | Dec 9, 2025 | A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi... |
| CVE-2025-40800 | HIGH | 7.4 | 0.2% | Dec 9, 2025 | A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), NX V2... |
| CVE-2025-40344 | HIGH | 7.8 | 0.2% | Dec 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: avs: Disable periods-elapsed work when... |
| CVE-2025-40342 | HIGH | 8.8 | 0.2% | Dec 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: nvme-fc: use lock accessing port_state and rport st... |
| CVE-2025-40337 | HIGH | 8.2 | 0.2% | Dec 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: stmmac: Correctly handle Rx checksum offload e... |
| CVE-2025-40336 | HIGH | 8.8 | 0.2% | Dec 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/gpusvm: fix hmm_pfn_to_map_order() usage Handl... |
| CVE-2025-40334 | HIGH | 7.3 | 0.2% | Dec 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate userq buffer virtual address a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now