2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-62082MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nasir Uddin Generi...
CVE-2025-61074MEDIUM4.6A stored Cross Site Scripting (XSS) vulnerability in the bulletin board (SchwarzeBrett) in adata Software GmbH Mitarbeit...
CVE-2025-59132MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Badi Jones Duplicate Content Cure duplicate-content-cure allows Cross...
CVE-2025-59029MEDIUM5.3An attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the...
CVE-2025-49350MEDIUM4.3Missing Authorization vulnerability in marcoingraiti Actionwear products sync actionwear-products-sync allows Exploiting...
CVE-2025-49348MEDIUM5.3Missing Authorization vulnerability in Hype Hype pico allows Exploiting Incorrectly Configured Access Control Security L...
CVE-2025-42904MEDIUM6.5Due to an Information Disclosure vulnerability in Application Server ABAP, an authenticated attacker could read unmasked...
CVE-2025-42896MEDIUM5.4SAP BusinessObjects Business Intelligence Platform lets an unauthenticated remote attacker send crafted requests through...
CVE-2025-42891MEDIUM5.5Due to a missing authorization check in SAP Enterprise Search for ABAP, an attacker with high privileges may read and ex...
CVE-2025-42875MEDIUM6.6The SAP Internet Communication Framework does not conduct any authentication checks for features that need user identifi...
CVE-2025-42873MEDIUM5.9SAPUI5 (and OpenUI5) packages use outdated 3rd party libraries with known security vulnerabilities. When markdown-it enc...
CVE-2025-42872MEDIUM6.1Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, an unauthenticated attacker could ...
CVE-2025-41697MEDIUM6.8An attacker can use an undocumented UART port on the PCB as a side-channel to get root access e.g. with the credentia...
CVE-2025-41696MEDIUM4.6An attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained ...
CVE-2025-41694MEDIUM6.5A low privileged remote attacker can run the webshell with an empty command containing whitespace. The server will then ...
CVE-2025-41693MEDIUM4.3A low privileged remote attacker can use the ssh feature to execute commands directly after login. The process stays ope...
CVE-2025-41692MEDIUM6.8A high privileged remote attacker with admin privileges for the webUI can brute-force the "root" and "user" passwords of...
CVE-2025-40941MEDIUM4.3A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected devices exposes server info...
CVE-2025-40940MEDIUM6.9A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application exhibits incons...
CVE-2025-40939MEDIUM5.1A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device contains a USB port ...
CVE-2025-40935MEDIUM4.3A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.10.1), RUGGEDCOM RS416Pv2 V5.X (All ver...
CVE-2025-40819MEDIUM4.3A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications do ...
CVE-2025-40807MEDIUM5.4A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerabl...
CVE-2025-40806MEDIUM6.9A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerabl...
CVE-2025-14345MEDIUM5.4A post-authentication flaw in the network two-phase commit protocol used for cross-shard transactions in MongoDB Server ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now