2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-11822MEDIUM6.4The WP Bootstrap Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bootstrap_tab' shortcod...
CVE-2025-11821MEDIUM6.4The Woocommerce – Products By Custom Tax plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'woo_...
CVE-2025-11805MEDIUM6.4The Skip to Timestamp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'skipto' shortcode in al...
CVE-2025-11532MEDIUM5.3The Wisly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1...
CVE-2025-11129MEDIUM6.4The Include Fussball.de Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api' and 'typ...
CVE-2025-42924MEDIUM6.1SAP S/4HANA landscape SAP E-Recruiting BSP allows an unauthenticated attacker to craft malicious links, when clicked the...
CVE-2025-42919MEDIUM5.3Due to an Information Disclosure vulnerability in SAP NetWeaver Application Server Java, internal metadata files could b...
CVE-2025-42899MEDIUM4.3SAP S4CORE (Manage journal entries) does not perform necessary authorization checks for an authenticated user resulting ...
CVE-2025-42897MEDIUM5.3Due to information disclosure vulnerability in anonymous API provided by SAP Business One (SLD), an attacker with normal...
CVE-2025-42895MEDIUM6.9Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a high-privilege locally a...
CVE-2025-42894MEDIUM6.8Due to a Path Traversal vulnerability in SAP Business Connector, an attacker authenticated as an administrator with adja...
CVE-2025-42893MEDIUM6.1Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL...
CVE-2025-42892MEDIUM6.8Due to an OS Command Injection vulnerability in SAP Business Connector, an authenticated attacker with administrative ac...
CVE-2025-42889MEDIUM5.4SAP Starter Solution allows an authenticated attacker to execute crafted database queries, thereby exposing the back-end...
CVE-2025-42888MEDIUM5.5SAP GUI for Windows may allow a highly privileged user on the affected client PC to locally access sensitive information...
CVE-2025-42886MEDIUM6.1Due to a Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could...
CVE-2025-42885MEDIUM5.8Due to missing authentication, SAP HANA 2.0 (hdbrss) allows an unauthenticated attacker to call a remote-enabled functio...
CVE-2025-42884MEDIUM6.5SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject JNDI environment properties or pass a URL u...
CVE-2025-42882MEDIUM4.3Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with basic ...
CVE-2025-31719MEDIUM5.1In TEE EcDSA algorithm, there is a possible memory consistency issue. This could lead to generated incorrect signature r...
CVE-2025-64529MEDIUM6.5SpiceDB is an open source database system for creating and managing security-critical application permissions. In versio...
CVE-2025-64504MEDIUM5Langfuse is an open source large language model engineering platform. Starting in version 2.70.0 and prior to versions 2...
CVE-2025-64502MEDIUM6.9Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. The MongoDB `exp...
CVE-2025-64167MEDIUM6.1Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to a cross-sit...
CVE-2025-63397MEDIUM6.5Improper input validation in OneFlow v0.9.0 allows attackers to cause a segmentation fault via adding a Python sequence ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now