2025 CVE Vulnerabilities
45,280 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4317 | HIGH | 8.8 | 1.1% | May 13, 2025 | The TheGem theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the thegem... |
| CVE-2025-3107 | MEDIUM | 6.5 | 0.3% | May 13, 2025 | The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby' parameter in all versio... |
| CVE-2025-4632 | CRITICAL | 9.8 | 24.0% | May 13, 2025 | Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 2... |
| CVE-2025-22249 | HIGH | 8.2 | 0.3% | May 13, 2025 | VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this... |
| CVE-2025-22246 | HIGH | 7.5 | 0.2% | May 13, 2025 | Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs. |
| CVE-2025-4396 | HIGH | 7.5 | 2.6% | May 13, 2025 | The Relevanssi – A Better Search plugin for WordPress is vulnerable to time-based SQL Injection via the cats and tags qu... |
| CVE-2025-47864 | — | — | — | May 13, 2025 | Rejected reason: Not used |
| CVE-2025-47863 | — | — | — | May 13, 2025 | Rejected reason: Not used |
| CVE-2025-47862 | — | — | — | May 13, 2025 | Rejected reason: Not used |
| CVE-2025-47861 | — | — | — | May 13, 2025 | Rejected reason: Not used |
| CVE-2025-47860 | — | — | — | May 13, 2025 | Rejected reason: Not used |
| CVE-2025-47859 | — | — | — | May 13, 2025 | Rejected reason: Not used |
| CVE-2025-47858 | — | — | — | May 13, 2025 | Rejected reason: Not used |
| CVE-2025-35471 | HIGH | 7.8 | 0.2% | May 13, 2025 | conda-forge openssl-feedstock before 066e83c (2024-05-20), on Microsoft Windows, configures OpenSSL to use an OPENSSLDIR... |
| CVE-2025-43011 | HIGH | 7.7 | 0.3% | May 13, 2025 | Under certain conditions, SAP Landscape Transformation's PCL Basis module does not perform the necessary authorization c... |
| CVE-2025-43010 | HIGH | 8.3 | 0.4% | May 13, 2025 | SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) allows an authenticated attacker with SAP ... |
| CVE-2025-43009 | MEDIUM | 6.3 | 0.2% | May 13, 2025 | SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing a... |
| CVE-2025-43008 | MEDIUM | 5.8 | 0.3% | May 13, 2025 | Due to missing authorization check, an unauthorized user can view the files of other company. This might lead to disclos... |
| CVE-2025-43007 | MEDIUM | 6.3 | 0.2% | May 13, 2025 | SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing a... |
| CVE-2025-43006 | MEDIUM | 6.1 | 0.3% | May 13, 2025 | SAP Supplier Relationship Management (Master Data Management Catalogue) allows an unauthenticated attacker to execute ma... |
| CVE-2025-43005 | MEDIUM | 4.3 | 0.2% | May 13, 2025 | SAP GUI for Windows allows an unauthenticated attacker to exploit insecure obfuscation algorithms used by the GuiXT appl... |
| CVE-2025-43004 | MEDIUM | 5.3 | 0.3% | May 13, 2025 | Due to a security misconfiguration vulnerability, customers can develop Production Operator Dashboards (PODs) that enabl... |
| CVE-2025-43003 | MEDIUM | 6.4 | 0.3% | May 13, 2025 | SAP S/4 HANA allows an authenticated attacker with user privileges to configure a field not intended for their access an... |
| CVE-2025-43002 | MEDIUM | 4.3 | 0.3% | May 13, 2025 | SAP S4CORE OData meta-data property allows an authenticated attacker to access restricted information due to missing aut... |
| CVE-2025-43000 | HIGH | 7.9 | 0.1% | May 13, 2025 | Under certain conditions Promotion Management Wizard (PMW) allows an attacker to access information which would otherwis... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now