2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40772 | MEDIUM | 6.1 | 0.3% | Oct 14, 2025 | A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications are vulnera... |
| CVE-2025-20724 | MEDIUM | 5.5 | 0.1% | Oct 14, 2025 | In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local inf... |
| CVE-2025-20722 | MEDIUM | 5.5 | 0.1% | Oct 14, 2025 | In gnss driver, there is a possible out of bounds read due to an integer overflow. This could lead to local information ... |
| CVE-2025-55078 | MEDIUM | 5.5 | 0.2% | Oct 14, 2025 | In Eclipse ThreadX before version 6.4.3, an attacker can cause a denial of service (crash) by providing a pointer to a r... |
| CVE-2025-41707 | MEDIUM | 5.3 | 1.4% | Oct 14, 2025 | The websocket handler is vulnerable to a denial of service condition. An unauthenticated remote attacker can send a craf... |
| CVE-2025-41706 | MEDIUM | 5.3 | 1.7% | Oct 14, 2025 | The webserver is vulnerable to a denial of service condition. An unauthenticated remote attacker can craft a special GET... |
| CVE-2025-41705 | MEDIUM | 6.8 | 0.4% | Oct 14, 2025 | An unauthenticated remote attacker (MITM) can intercept the websocket messages to gain access to the login credentials f... |
| CVE-2025-41704 | MEDIUM | 5.3 | 1.5% | Oct 14, 2025 | An unauthanticated remote attacker can perform a DoS of the Modbus service by sending a specific function and sub-functi... |
| CVE-2025-10732 | MEDIUM | 4.3 | 0.2% | Oct 14, 2025 | The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Information Dis... |
| CVE-2025-10357 | MEDIUM | 6.1 | 0.2% | Oct 14, 2025 | The Simple SEO WordPress plugin before 2.0.32 does not sanitise and escape some parameters when outputing them in the pa... |
| CVE-2025-42939 | MEDIUM | 4.3 | 0.2% | Oct 14, 2025 | SAP S/4HANA (Manage Processing Rules - For Bank Statements) allows an authenticated attacker with basic privileges to de... |
| CVE-2025-42908 | MEDIUM | 5.4 | 0.1% | Oct 14, 2025 | Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP, an authenticated ... |
| CVE-2025-42906 | MEDIUM | 5.3 | 0.4% | Oct 14, 2025 | SAP Commerce Cloud contains a path traversal vulnerability that may allow users to access web applications such as the A... |
| CVE-2025-42903 | MEDIUM | 4.3 | 0.3% | Oct 14, 2025 | A vulnerability in SAP Financial Service Claims Management RFC function ICL_USER_GET_NAME_AND_ADDRESS allows user enumer... |
| CVE-2025-42902 | MEDIUM | 5.3 | 0.4% | Oct 14, 2025 | Due to the memory corruption vulnerability in SAP NetWeaver AS ABAP and ABAP Platform, an unauthenticated attacker can s... |
| CVE-2025-42901 | MEDIUM | 5.4 | 0.2% | Oct 14, 2025 | SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript payloads which could be e... |
| CVE-2025-62392 | MEDIUM | 6.5 | 0.8% | Oct 13, 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar... |
| CVE-2025-62391 | MEDIUM | 6.5 | 0.8% | Oct 13, 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar... |
| CVE-2025-62390 | MEDIUM | 6.5 | 1.6% | Oct 13, 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar... |
| CVE-2025-62389 | MEDIUM | 6.5 | 1.6% | Oct 13, 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar... |
| CVE-2025-62388 | MEDIUM | 6.5 | 0.8% | Oct 13, 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar... |
| CVE-2025-62387 | MEDIUM | 6.5 | 1.6% | Oct 13, 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar... |
| CVE-2025-62386 | MEDIUM | 6.5 | 0.8% | Oct 13, 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar... |
| CVE-2025-62385 | MEDIUM | 6.5 | 0.8% | Oct 13, 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar... |
| CVE-2025-62384 | MEDIUM | 6.5 | 0.8% | Oct 13, 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now