2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-20683 | CRITICAL | 9.8 | 0.5% | Jul 8, 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es... |
| CVE-2025-20682 | CRITICAL | 9.8 | 0.5% | Jul 8, 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es... |
| CVE-2025-20681 | CRITICAL | 9.8 | 0.5% | Jul 8, 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es... |
| CVE-2025-20680 | CRITICAL | 9.8 | 0.7% | Jul 8, 2025 | In Bluetooth driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local ... |
| CVE-2025-7155 | CRITICAL | 9.8 | 0.5% | Jul 8, 2025 | A vulnerability, which was classified as critical, was found in PHPGurukul Online Notes Sharing System 1.0. This affects... |
| CVE-2025-42980 | CRITICAL | 9.1 | 0.7% | Jul 8, 2025 | SAP NetWeaver Enterprise Portal Federated Portal Network is vulnerable when a privileged user can upload untrusted or ma... |
| CVE-2025-42967 | CRITICAL | 9.9 | 0.9% | Jul 8, 2025 | SAP S/4HANA and SAP SCM Characteristic Propagation has remote code execution vulnerability. This allows an attacker with... |
| CVE-2025-42966 | CRITICAL | 9.1 | 0.7% | Jul 8, 2025 | SAP NetWeaver XML Data Archiving Service allows an authenticated attacker with administrative privileges to exploit an i... |
| CVE-2025-42964 | CRITICAL | 9.1 | 0.7% | Jul 8, 2025 | SAP NetWeaver Enterprise Portal Administration is vulnerable when a privileged user can upload untrusted or malicious co... |
| CVE-2025-42963 | CRITICAL | 9.1 | 0.7% | Jul 8, 2025 | A critical vulnerability in SAP NetWeaver Application server for Java Log Viewer enables authenticated administrator use... |
| CVE-2025-7147 | CRITICAL | 9.8 | 0.5% | Jul 7, 2025 | A vulnerability has been found in CodeAstro Patient Record Management System 1.0 and classified as critical. Affected by... |
| CVE-2025-53499 | CRITICAL | 9.1 | 0.3% | Jul 7, 2025 | Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Unauthorized Access... |
| CVE-2025-53495 | CRITICAL | 9.1 | 0.3% | Jul 7, 2025 | Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Unauthorized Access... |
| CVE-2025-7136 | CRITICAL | 9.8 | 0.4% | Jul 7, 2025 | A vulnerability, which was classified as critical, was found in Campcodes Online Recruitment Management System 1.0. Affe... |
| CVE-2025-53529 | CRITICAL | 9.8 | 0.5% | Jul 7, 2025 | WeGIA is a web manager for charitable institutions. An SQL Injection vulnerability was identified in the /html/funcionar... |
| CVE-2025-53527 | CRITICAL | 9.8 | 0.4% | Jul 7, 2025 | WeGIA is a web manager for charitable institutions. A Time-Based Blind SQL Injection vulnerability was discovered in the... |
| CVE-2025-7135 | CRITICAL | 9.8 | 0.4% | Jul 7, 2025 | A vulnerability, which was classified as critical, has been found in Campcodes Online Recruitment Management System 1.0.... |
| CVE-2025-7134 | CRITICAL | 9.8 | 0.4% | Jul 7, 2025 | A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. This vulnerabili... |
| CVE-2025-47202 | CRITICAL | 9.1 | 0.4% | Jul 7, 2025 | In RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 13... |
| CVE-2025-45479 | CRITICAL | 9.8 | 0.7% | Jul 7, 2025 | Insufficient security mechanisms for created containers in educoder challenges v1.0 allow attackers to execute arbitrary... |
| CVE-2025-45065 | CRITICAL | 9.8 | 0.4% | Jul 7, 2025 | employee record management system in php and mysql v1 was discovered to contain a SQL injection vulnerability via the lo... |
| CVE-2025-43933 | CRITICAL | 9.8 | 0.4% | Jul 7, 2025 | fblog through 983bede allows account takeover via the password reset feature because SERVER_NAME is not configured and t... |
| CVE-2025-43932 | CRITICAL | 9.8 | 0.3% | Jul 7, 2025 | JobCenter through 7e7b0b2 allows account takeover via the password reset feature because SERVER_NAME is not configured a... |
| CVE-2025-43931 | CRITICAL | 9.8 | 0.3% | Jul 7, 2025 | flask-boilerplate through a170e7c allows account takeover via the password reset feature because SERVER_NAME is not conf... |
| CVE-2025-7132 | CRITICAL | 9.8 | 0.5% | Jul 7, 2025 | A vulnerability was found in Campcodes Payroll Management System 1.0. It has been rated as critical. Affected by this is... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now