2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11822 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The WP Bootstrap Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bootstrap_tab' shortcod... |
| CVE-2025-11821 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Woocommerce – Products By Custom Tax plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'woo_... |
| CVE-2025-11805 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Skip to Timestamp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'skipto' shortcode in al... |
| CVE-2025-11532 | MEDIUM | 5.3 | 0.2% | Nov 11, 2025 | The Wisly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1... |
| CVE-2025-11129 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Include Fussball.de Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api' and 'typ... |
| CVE-2025-42924 | MEDIUM | 6.1 | 0.2% | Nov 11, 2025 | SAP S/4HANA landscape SAP E-Recruiting BSP allows an unauthenticated attacker to craft malicious links, when clicked the... |
| CVE-2025-42919 | MEDIUM | 5.3 | 0.4% | Nov 11, 2025 | Due to an Information Disclosure vulnerability in SAP NetWeaver Application Server Java, internal metadata files could b... |
| CVE-2025-42899 | MEDIUM | 4.3 | 0.2% | Nov 11, 2025 | SAP S4CORE (Manage journal entries) does not perform necessary authorization checks for an authenticated user resulting ... |
| CVE-2025-42897 | MEDIUM | 5.3 | 0.2% | Nov 11, 2025 | Due to information disclosure vulnerability in anonymous API provided by SAP Business One (SLD), an attacker with normal... |
| CVE-2025-42895 | MEDIUM | 6.9 | 0.1% | Nov 11, 2025 | Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a high-privilege locally a... |
| CVE-2025-42894 | MEDIUM | 6.8 | 0.3% | Nov 11, 2025 | Due to a Path Traversal vulnerability in SAP Business Connector, an attacker authenticated as an administrator with adja... |
| CVE-2025-42893 | MEDIUM | 6.1 | 0.2% | Nov 11, 2025 | Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL... |
| CVE-2025-42892 | MEDIUM | 6.8 | 0.9% | Nov 11, 2025 | Due to an OS Command Injection vulnerability in SAP Business Connector, an authenticated attacker with administrative ac... |
| CVE-2025-42889 | MEDIUM | 5.4 | 0.2% | Nov 11, 2025 | SAP Starter Solution allows an authenticated attacker to execute crafted database queries, thereby exposing the back-end... |
| CVE-2025-42888 | MEDIUM | 5.5 | 0.1% | Nov 11, 2025 | SAP GUI for Windows may allow a highly privileged user on the affected client PC to locally access sensitive information... |
| CVE-2025-42886 | MEDIUM | 6.1 | 0.2% | Nov 11, 2025 | Due to a Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could... |
| CVE-2025-42885 | MEDIUM | 5.8 | 0.3% | Nov 11, 2025 | Due to missing authentication, SAP HANA 2.0 (hdbrss) allows an unauthenticated attacker to call a remote-enabled functio... |
| CVE-2025-42884 | MEDIUM | 6.5 | 0.2% | Nov 11, 2025 | SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject JNDI environment properties or pass a URL u... |
| CVE-2025-42882 | MEDIUM | 4.3 | 0.2% | Nov 11, 2025 | Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with basic ... |
| CVE-2025-31719 | MEDIUM | 5.1 | 0.1% | Nov 11, 2025 | In TEE EcDSA algorithm, there is a possible memory consistency issue. This could lead to generated incorrect signature r... |
| CVE-2025-64529 | MEDIUM | 6.5 | 0.2% | Nov 10, 2025 | SpiceDB is an open source database system for creating and managing security-critical application permissions. In versio... |
| CVE-2025-64504 | MEDIUM | 5 | 0.3% | Nov 10, 2025 | Langfuse is an open source large language model engineering platform. Starting in version 2.70.0 and prior to versions 2... |
| CVE-2025-64502 | MEDIUM | 6.9 | 0.4% | Nov 10, 2025 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. The MongoDB `exp... |
| CVE-2025-64167 | MEDIUM | 6.1 | 0.2% | Nov 10, 2025 | Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to a cross-sit... |
| CVE-2025-63397 | MEDIUM | 6.5 | 0.3% | Nov 10, 2025 | Improper input validation in OneFlow v0.9.0 allows attackers to cause a segmentation fault via adding a Python sequence ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now