2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-7330MEDIUM6.5A cross-site request forgery security issue exists in the product and version listed. The vulnerability stems from missi...
CVE-2025-7329MEDIUM4.8A Stored Cross-Site Scripting security issue exists in the affected product that could potentially allow a malicious use...
CVE-2025-11718MEDIUM6.5When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool th...
CVE-2025-11716MEDIUM6.5Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnera...
CVE-2025-11712MEDIUM6.1A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encou...
CVE-2025-11711MEDIUM6.5There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnera...
CVE-2025-11498MEDIUM6.1An Improper Neutralization of Formula Elements in a CSV File vulnerability exists in System Diagnostics Manager (SDM) of...
CVE-2025-40774MEDIUM6.7A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications store user ...
CVE-2025-40773MEDIUM5.3A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications contains a ...
CVE-2025-40772MEDIUM6.1A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications are vulnera...
CVE-2025-20724MEDIUM5.5In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local inf...
CVE-2025-20722MEDIUM5.5In gnss driver, there is a possible out of bounds read due to an integer overflow. This could lead to local information ...
CVE-2025-55078MEDIUM5.5In Eclipse ThreadX before version 6.4.3, an attacker can cause a denial of service (crash) by providing a pointer to a r...
CVE-2025-41707MEDIUM5.3The websocket handler is vulnerable to a denial of service condition. An unauthenticated remote attacker can send a craf...
CVE-2025-41706MEDIUM5.3The webserver is vulnerable to a denial of service condition. An unauthenticated remote attacker can craft a special GET...
CVE-2025-41705MEDIUM6.8An unauthenticated remote attacker (MITM) can intercept the websocket messages to gain access to the login credentials f...
CVE-2025-41704MEDIUM5.3An unauthanticated remote attacker can perform a DoS of the Modbus service by sending a specific function and sub-functi...
CVE-2025-10732MEDIUM4.3The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Information Dis...
CVE-2025-10357MEDIUM6.1The Simple SEO WordPress plugin before 2.0.32 does not sanitise and escape some parameters when outputing them in the pa...
CVE-2025-42939MEDIUM4.3SAP S/4HANA (Manage Processing Rules - For Bank Statements) allows an authenticated attacker with basic privileges to de...
CVE-2025-42908MEDIUM5.4Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP, an authenticated ...
CVE-2025-42906MEDIUM5.3SAP Commerce Cloud contains a path traversal vulnerability that may allow users to access web applications such as the A...
CVE-2025-42903MEDIUM4.3A vulnerability in SAP Financial Service Claims Management RFC function ICL_USER_GET_NAME_AND_ADDRESS allows user enumer...
CVE-2025-42902MEDIUM5.3Due to the memory corruption vulnerability in SAP NetWeaver AS ABAP and ABAP Platform, an unauthenticated attacker can s...
CVE-2025-42901MEDIUM5.4SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript payloads which could be e...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now