2025 CVE Vulnerabilities

45,168 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-9058MEDIUM6.4The Mikado Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and ...
CVE-2025-9489MEDIUM5The The WP-Members Membership Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions...
CVE-2025-43777MEDIUM5.3Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024...
CVE-2025-43778MEDIUM6.1A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 th...
CVE-2025-42938MEDIUM6.1Due to a Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform, an unauthenticated attacker could ...
CVE-2025-42930MEDIUM6.5SAP Business Planning and Consolidation allows an authenticated standard user to call a function module by crafting spec...
CVE-2025-42926MEDIUM5.3SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access inter...
CVE-2025-42925MEDIUM4.3Due to the lack of randomness in assigning Object Identifiers in the SAP NetWeaver AS JAVA IIOP service, an authenticate...
CVE-2025-42923MEDIUM4.3Due to insufficient CSRF protection in SAP Fiori App Manage Work Center Groups, an authenticated user could be tricked b...
CVE-2025-42920MEDIUM6.1Due to a Cross-Site Scripting (XSS) vulnerability in the SAP Supplier Relationship Management, an unauthenticated attack...
CVE-2025-42918MEDIUM4.3SAP NetWeaver Application Server for ABAP allows authenticated users with access to background processing to gain unauth...
CVE-2025-42917MEDIUM6.5SAP HCM Approve Timesheets Fiori 2.0 application does not perform necessary authorization checks for an authenticated us...
CVE-2025-42915MEDIUM5.4Fiori app Manage Payment Blocks does not perform the necessary authorization checks, allowing an attacker with basic use...
CVE-2025-42912MEDIUM6.5SAP HCM My Timesheet Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, re...
CVE-2025-42911MEDIUM4.3SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled function module, which could...
CVE-2025-10121MEDIUM6.3A flaw has been found in uverif up to 3.2. This affects the function addbatch of the file /admin/kami_list. This manipul...
CVE-2025-10117MEDIUM5.4A weakness has been identified in SourceCodester Simple To-Do List System 1.0. Impacted is an unknown function of the fi...
CVE-2025-43763MEDIUM6.5A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP...
CVE-2025-58752MEDIUM5.3Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files o...
CVE-2025-58751MEDIUM5.3Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting w...
CVE-2025-58452MEDIUM6.1WeGIA is a Web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified ...
CVE-2025-57815MEDIUM6.5Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Admin UI login endpoint relies ...
CVE-2025-57766MEDIUM4.8Fides is an open-source privacy engineering platform. Prior to version 2.69.1, admin UI user password changes in Fides d...
CVE-2025-53838MEDIUM5.4LinkAce is a self-hosted archive to collect website links. A stored cross-site scripting (XSS) vulnerability was discove...
CVE-2025-43722MEDIUM6.7Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper privilege management vulnerability. A high privi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now