2025 CVE Vulnerabilities

45,280 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-4317HIGH8.8The TheGem theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the thegem...
CVE-2025-3107MEDIUM6.5The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby' parameter in all versio...
CVE-2025-4632CRITICAL9.8Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 2...
CVE-2025-22249HIGH8.2VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this...
CVE-2025-22246HIGH7.5Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs.
CVE-2025-4396HIGH7.5The Relevanssi – A Better Search plugin for WordPress is vulnerable to time-based SQL Injection via the cats and tags qu...
CVE-2025-47864Rejected reason: Not used
CVE-2025-47863Rejected reason: Not used
CVE-2025-47862Rejected reason: Not used
CVE-2025-47861Rejected reason: Not used
CVE-2025-47860Rejected reason: Not used
CVE-2025-47859Rejected reason: Not used
CVE-2025-47858Rejected reason: Not used
CVE-2025-35471HIGH7.8conda-forge openssl-feedstock before 066e83c (2024-05-20), on Microsoft Windows, configures OpenSSL to use an OPENSSLDIR...
CVE-2025-43011HIGH7.7Under certain conditions, SAP Landscape Transformation's PCL Basis module does not perform the necessary authorization c...
CVE-2025-43010HIGH8.3SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) allows an authenticated attacker with SAP ...
CVE-2025-43009MEDIUM6.3SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing a...
CVE-2025-43008MEDIUM5.8Due to missing authorization check, an unauthorized user can view the files of other company. This might lead to disclos...
CVE-2025-43007MEDIUM6.3SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing a...
CVE-2025-43006MEDIUM6.1SAP Supplier Relationship Management (Master Data Management Catalogue) allows an unauthenticated attacker to execute ma...
CVE-2025-43005MEDIUM4.3SAP GUI for Windows allows an unauthenticated attacker to exploit insecure obfuscation algorithms used by the GuiXT appl...
CVE-2025-43004MEDIUM5.3Due to a security misconfiguration vulnerability, customers can develop Production Operator Dashboards (PODs) that enabl...
CVE-2025-43003MEDIUM6.4SAP S/4 HANA allows an authenticated attacker with user privileges to configure a field not intended for their access an...
CVE-2025-43002MEDIUM4.3SAP S4CORE OData meta-data property allows an authenticated attacker to access restricted information due to missing aut...
CVE-2025-43000HIGH7.9Under certain conditions Promotion Management Wizard (PMW) allows an attacker to access information which would otherwis...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now