2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-7330 | MEDIUM | 6.5 | 0.2% | Oct 14, 2025 | A cross-site request forgery security issue exists in the product and version listed. The vulnerability stems from missi... |
| CVE-2025-7329 | MEDIUM | 4.8 | 0.2% | Oct 14, 2025 | A Stored Cross-Site Scripting security issue exists in the affected product that could potentially allow a malicious use... |
| CVE-2025-11718 | MEDIUM | 6.5 | 0.2% | Oct 14, 2025 | When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool th... |
| CVE-2025-11716 | MEDIUM | 6.5 | 0.2% | Oct 14, 2025 | Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnera... |
| CVE-2025-11712 | MEDIUM | 6.1 | 0.3% | Oct 14, 2025 | A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encou... |
| CVE-2025-11711 | MEDIUM | 6.5 | 0.2% | Oct 14, 2025 | There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnera... |
| CVE-2025-11498 | MEDIUM | 6.1 | 0.3% | Oct 14, 2025 | An Improper Neutralization of Formula Elements in a CSV File vulnerability exists in System Diagnostics Manager (SDM) of... |
| CVE-2025-40774 | MEDIUM | 6.7 | 0.1% | Oct 14, 2025 | A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications store user ... |
| CVE-2025-40773 | MEDIUM | 5.3 | 0.2% | Oct 14, 2025 | A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications contains a ... |
| CVE-2025-40772 | MEDIUM | 6.1 | 0.3% | Oct 14, 2025 | A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications are vulnera... |
| CVE-2025-20724 | MEDIUM | 5.5 | 0.1% | Oct 14, 2025 | In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local inf... |
| CVE-2025-20722 | MEDIUM | 5.5 | 0.1% | Oct 14, 2025 | In gnss driver, there is a possible out of bounds read due to an integer overflow. This could lead to local information ... |
| CVE-2025-55078 | MEDIUM | 5.5 | 0.2% | Oct 14, 2025 | In Eclipse ThreadX before version 6.4.3, an attacker can cause a denial of service (crash) by providing a pointer to a r... |
| CVE-2025-41707 | MEDIUM | 5.3 | 1.4% | Oct 14, 2025 | The websocket handler is vulnerable to a denial of service condition. An unauthenticated remote attacker can send a craf... |
| CVE-2025-41706 | MEDIUM | 5.3 | 1.7% | Oct 14, 2025 | The webserver is vulnerable to a denial of service condition. An unauthenticated remote attacker can craft a special GET... |
| CVE-2025-41705 | MEDIUM | 6.8 | 0.4% | Oct 14, 2025 | An unauthenticated remote attacker (MITM) can intercept the websocket messages to gain access to the login credentials f... |
| CVE-2025-41704 | MEDIUM | 5.3 | 1.5% | Oct 14, 2025 | An unauthanticated remote attacker can perform a DoS of the Modbus service by sending a specific function and sub-functi... |
| CVE-2025-10732 | MEDIUM | 4.3 | 0.2% | Oct 14, 2025 | The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Information Dis... |
| CVE-2025-10357 | MEDIUM | 6.1 | 0.2% | Oct 14, 2025 | The Simple SEO WordPress plugin before 2.0.32 does not sanitise and escape some parameters when outputing them in the pa... |
| CVE-2025-42939 | MEDIUM | 4.3 | 0.2% | Oct 14, 2025 | SAP S/4HANA (Manage Processing Rules - For Bank Statements) allows an authenticated attacker with basic privileges to de... |
| CVE-2025-42908 | MEDIUM | 5.4 | 0.1% | Oct 14, 2025 | Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP, an authenticated ... |
| CVE-2025-42906 | MEDIUM | 5.3 | 0.4% | Oct 14, 2025 | SAP Commerce Cloud contains a path traversal vulnerability that may allow users to access web applications such as the A... |
| CVE-2025-42903 | MEDIUM | 4.3 | 0.3% | Oct 14, 2025 | A vulnerability in SAP Financial Service Claims Management RFC function ICL_USER_GET_NAME_AND_ADDRESS allows user enumer... |
| CVE-2025-42902 | MEDIUM | 5.3 | 0.4% | Oct 14, 2025 | Due to the memory corruption vulnerability in SAP NetWeaver AS ABAP and ABAP Platform, an unauthenticated attacker can s... |
| CVE-2025-42901 | MEDIUM | 5.4 | 0.2% | Oct 14, 2025 | SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript payloads which could be e... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now