2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-42923MEDIUM4.3Due to insufficient CSRF protection in SAP Fiori App Manage Work Center Groups, an authenticated user could be tricked b...
CVE-2025-42920MEDIUM6.1Due to a Cross-Site Scripting (XSS) vulnerability in the SAP Supplier Relationship Management, an unauthenticated attack...
CVE-2025-42918MEDIUM4.3SAP NetWeaver Application Server for ABAP allows authenticated users with access to background processing to gain unauth...
CVE-2025-42917MEDIUM6.5SAP HCM Approve Timesheets Fiori 2.0 application does not perform necessary authorization checks for an authenticated us...
CVE-2025-42915MEDIUM5.4Fiori app Manage Payment Blocks does not perform the necessary authorization checks, allowing an attacker with basic use...
CVE-2025-42912MEDIUM6.5SAP HCM My Timesheet Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, re...
CVE-2025-42911MEDIUM4.3SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled function module, which could...
CVE-2025-10121MEDIUM6.3A flaw has been found in uverif up to 3.2. This affects the function addbatch of the file /admin/kami_list. This manipul...
CVE-2025-10117MEDIUM5.4A weakness has been identified in SourceCodester Simple To-Do List System 1.0. Impacted is an unknown function of the fi...
CVE-2025-43763MEDIUM6.5A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP...
CVE-2025-58752MEDIUM5.3Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files o...
CVE-2025-58751MEDIUM5.3Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting w...
CVE-2025-58452MEDIUM6.1WeGIA is a Web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified ...
CVE-2025-57815MEDIUM6.5Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Admin UI login endpoint relies ...
CVE-2025-57766MEDIUM4.8Fides is an open-source privacy engineering platform. Prior to version 2.69.1, admin UI user password changes in Fides d...
CVE-2025-53838MEDIUM5.4LinkAce is a self-hosted archive to collect website links. A stored cross-site scripting (XSS) vulnerability was discove...
CVE-2025-43722MEDIUM6.7Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper privilege management vulnerability. A high privi...
CVE-2025-10099MEDIUM4.8A weakness has been identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functiona...
CVE-2025-10096MEDIUM6.5A vulnerability was determined in SimStudioAI sim up to 1.0.0. This affects an unknown function of the file apps/sim/app...
CVE-2025-7709MEDIUM6.9An integer overflow exists in the FTS5 https://sqlite.org/fts5.html  extension. It occurs when the size of an array of ...
CVE-2025-40929MEDIUM5.6Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSO...
CVE-2025-3212MEDIUM5.3Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge...
CVE-2025-40642MEDIUM5.1Reflected Cross-Site Scripting (XSS) vulnerability in WebWork, which allows remote attackers to execute arbitrary code t...
CVE-2025-40641MEDIUM5.1Cross-site Scripting (XSS) vulnerability stored in Multi-Purpose Inventory Management System, consisting of a stored XSS...
CVE-2025-58782MEDIUM6.5Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now