2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-42904 | MEDIUM | 6.5 | 0.3% | Dec 9, 2025 | Due to an Information Disclosure vulnerability in Application Server ABAP, an authenticated attacker could read unmasked... |
| CVE-2025-42896 | MEDIUM | 5.4 | 0.3% | Dec 9, 2025 | SAP BusinessObjects Business Intelligence Platform lets an unauthenticated remote attacker send crafted requests through... |
| CVE-2025-42891 | MEDIUM | 5.5 | 0.3% | Dec 9, 2025 | Due to a missing authorization check in SAP Enterprise Search for ABAP, an attacker with high privileges may read and ex... |
| CVE-2025-42875 | MEDIUM | 6.6 | 0.3% | Dec 9, 2025 | The SAP Internet Communication Framework does not conduct any authentication checks for features that need user identifi... |
| CVE-2025-42873 | MEDIUM | 5.9 | 0.3% | Dec 9, 2025 | SAPUI5 (and OpenUI5) packages use outdated 3rd party libraries with known security vulnerabilities. When markdown-it enc... |
| CVE-2025-42872 | MEDIUM | 6.1 | 0.2% | Dec 9, 2025 | Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, an unauthenticated attacker could ... |
| CVE-2025-41697 | MEDIUM | 6.8 | 0.2% | Dec 9, 2025 | An attacker can use an undocumented UART port on the PCB as a side-channel to get root access e.g. with the credentia... |
| CVE-2025-41696 | MEDIUM | 4.6 | 0.2% | Dec 9, 2025 | An attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained ... |
| CVE-2025-41694 | MEDIUM | 6.5 | 0.4% | Dec 9, 2025 | A low privileged remote attacker can run the webshell with an empty command containing whitespace. The server will then ... |
| CVE-2025-41693 | MEDIUM | 4.3 | 0.4% | Dec 9, 2025 | A low privileged remote attacker can use the ssh feature to execute commands directly after login. The process stays ope... |
| CVE-2025-41692 | MEDIUM | 6.8 | 0.3% | Dec 9, 2025 | A high privileged remote attacker with admin privileges for the webUI can brute-force the "root" and "user" passwords of... |
| CVE-2025-40941 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected devices exposes server info... |
| CVE-2025-40940 | MEDIUM | 6.9 | 0.3% | Dec 9, 2025 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application exhibits incons... |
| CVE-2025-40939 | MEDIUM | 5.1 | 0.2% | Dec 9, 2025 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device contains a USB port ... |
| CVE-2025-40935 | MEDIUM | 5.3 | 0.2% | Dec 9, 2025 | A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.10.1), RUGGEDCOM RS416Pv2 V5.X (All ver... |
| CVE-2025-40819 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications do ... |
| CVE-2025-40807 | MEDIUM | 5.4 | 0.3% | Dec 9, 2025 | A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerabl... |
| CVE-2025-40806 | MEDIUM | 6.9 | 0.4% | Dec 9, 2025 | A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerabl... |
| CVE-2025-14345 | MEDIUM | 5.4 | 0.2% | Dec 9, 2025 | A post-authentication flaw in the network two-phase commit protocol used for cross-shard transactions in MongoDB Server ... |
| CVE-2025-14331 | MEDIUM | 6.5 | 0.2% | Dec 9, 2025 | Same-origin policy bypass in the Request Handling component. This vulnerability was fixed in Firefox 146, Firefox ESR 11... |
| CVE-2025-14311 | MEDIUM | 6.8 | 0.2% | Dec 9, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JMRI.This issue affects ... |
| CVE-2025-14284 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | Versions of the package @tiptap/extension-link before 2.10.4 are vulnerable to Cross-site Scripting (XSS) due to unsanit... |
| CVE-2025-13642 | MEDIUM | 5.4 | 0.4% | Dec 9, 2025 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres... |
| CVE-2025-13070 | MEDIUM | 6.6 | 0.4% | Dec 9, 2025 | The CSV to SortTable WordPress plugin through 4.2 does not validate some shortcode attributes before using them to gener... |
| CVE-2025-13031 | MEDIUM | 5.9 | 0.2% | Dec 9, 2025 | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.13 does not sanitize and escape some of its settings, which c... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now