2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-42904MEDIUM6.5Due to an Information Disclosure vulnerability in Application Server ABAP, an authenticated attacker could read unmasked...
CVE-2025-42896MEDIUM5.4SAP BusinessObjects Business Intelligence Platform lets an unauthenticated remote attacker send crafted requests through...
CVE-2025-42891MEDIUM5.5Due to a missing authorization check in SAP Enterprise Search for ABAP, an attacker with high privileges may read and ex...
CVE-2025-42875MEDIUM6.6The SAP Internet Communication Framework does not conduct any authentication checks for features that need user identifi...
CVE-2025-42873MEDIUM5.9SAPUI5 (and OpenUI5) packages use outdated 3rd party libraries with known security vulnerabilities. When markdown-it enc...
CVE-2025-42872MEDIUM6.1Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, an unauthenticated attacker could ...
CVE-2025-41697MEDIUM6.8An attacker can use an undocumented UART port on the PCB as a side-channel to get root access e.g. with the credentia...
CVE-2025-41696MEDIUM4.6An attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained ...
CVE-2025-41694MEDIUM6.5A low privileged remote attacker can run the webshell with an empty command containing whitespace. The server will then ...
CVE-2025-41693MEDIUM4.3A low privileged remote attacker can use the ssh feature to execute commands directly after login. The process stays ope...
CVE-2025-41692MEDIUM6.8A high privileged remote attacker with admin privileges for the webUI can brute-force the "root" and "user" passwords of...
CVE-2025-40941MEDIUM4.3A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected devices exposes server info...
CVE-2025-40940MEDIUM6.9A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application exhibits incons...
CVE-2025-40939MEDIUM5.1A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device contains a USB port ...
CVE-2025-40935MEDIUM5.3A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.10.1), RUGGEDCOM RS416Pv2 V5.X (All ver...
CVE-2025-40819MEDIUM4.3A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications do ...
CVE-2025-40807MEDIUM5.4A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerabl...
CVE-2025-40806MEDIUM6.9A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerabl...
CVE-2025-14345MEDIUM5.4A post-authentication flaw in the network two-phase commit protocol used for cross-shard transactions in MongoDB Server ...
CVE-2025-14331MEDIUM6.5Same-origin policy bypass in the Request Handling component. This vulnerability was fixed in Firefox 146, Firefox ESR 11...
CVE-2025-14311MEDIUM6.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JMRI.This issue affects ...
CVE-2025-14284MEDIUM6.1Versions of the package @tiptap/extension-link before 2.10.4 are vulnerable to Cross-site Scripting (XSS) due to unsanit...
CVE-2025-13642MEDIUM5.4The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres...
CVE-2025-13070MEDIUM6.6The CSV to SortTable WordPress plugin through 4.2 does not validate some shortcode attributes before using them to gener...
CVE-2025-13031MEDIUM5.9The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.13 does not sanitize and escape some of its settings, which c...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now