2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-40772MEDIUM6.1A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications are vulnera...
CVE-2025-20724MEDIUM5.5In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local inf...
CVE-2025-20722MEDIUM5.5In gnss driver, there is a possible out of bounds read due to an integer overflow. This could lead to local information ...
CVE-2025-55078MEDIUM5.5In Eclipse ThreadX before version 6.4.3, an attacker can cause a denial of service (crash) by providing a pointer to a r...
CVE-2025-41707MEDIUM5.3The websocket handler is vulnerable to a denial of service condition. An unauthenticated remote attacker can send a craf...
CVE-2025-41706MEDIUM5.3The webserver is vulnerable to a denial of service condition. An unauthenticated remote attacker can craft a special GET...
CVE-2025-41705MEDIUM6.8An unauthenticated remote attacker (MITM) can intercept the websocket messages to gain access to the login credentials f...
CVE-2025-41704MEDIUM5.3An unauthanticated remote attacker can perform a DoS of the Modbus service by sending a specific function and sub-functi...
CVE-2025-10732MEDIUM4.3The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Information Dis...
CVE-2025-10357MEDIUM6.1The Simple SEO WordPress plugin before 2.0.32 does not sanitise and escape some parameters when outputing them in the pa...
CVE-2025-42939MEDIUM4.3SAP S/4HANA (Manage Processing Rules - For Bank Statements) allows an authenticated attacker with basic privileges to de...
CVE-2025-42908MEDIUM5.4Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP, an authenticated ...
CVE-2025-42906MEDIUM5.3SAP Commerce Cloud contains a path traversal vulnerability that may allow users to access web applications such as the A...
CVE-2025-42903MEDIUM4.3A vulnerability in SAP Financial Service Claims Management RFC function ICL_USER_GET_NAME_AND_ADDRESS allows user enumer...
CVE-2025-42902MEDIUM5.3Due to the memory corruption vulnerability in SAP NetWeaver AS ABAP and ABAP Platform, an unauthenticated attacker can s...
CVE-2025-42901MEDIUM5.4SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript payloads which could be e...
CVE-2025-62392MEDIUM6.5SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar...
CVE-2025-62391MEDIUM6.5SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar...
CVE-2025-62390MEDIUM6.5SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar...
CVE-2025-62389MEDIUM6.5SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar...
CVE-2025-62388MEDIUM6.5SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar...
CVE-2025-62387MEDIUM6.5SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar...
CVE-2025-62386MEDIUM6.5SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar...
CVE-2025-62385MEDIUM6.5SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar...
CVE-2025-62384MEDIUM6.5SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now