2025 CVE Vulnerabilities
45,342 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-42923 | MEDIUM | 4.3 | 0.1% | Sep 9, 2025 | Due to insufficient CSRF protection in SAP Fiori App Manage Work Center Groups, an authenticated user could be tricked b... |
| CVE-2025-42920 | MEDIUM | 6.1 | 0.2% | Sep 9, 2025 | Due to a Cross-Site Scripting (XSS) vulnerability in the SAP Supplier Relationship Management, an unauthenticated attack... |
| CVE-2025-42918 | MEDIUM | 4.3 | 0.2% | Sep 9, 2025 | SAP NetWeaver Application Server for ABAP allows authenticated users with access to background processing to gain unauth... |
| CVE-2025-42917 | MEDIUM | 6.5 | 0.2% | Sep 9, 2025 | SAP HCM Approve Timesheets Fiori 2.0 application does not perform necessary authorization checks for an authenticated us... |
| CVE-2025-42915 | MEDIUM | 5.4 | 0.2% | Sep 9, 2025 | Fiori app Manage Payment Blocks does not perform the necessary authorization checks, allowing an attacker with basic use... |
| CVE-2025-42912 | MEDIUM | 6.5 | 0.2% | Sep 9, 2025 | SAP HCM My Timesheet Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, re... |
| CVE-2025-42911 | MEDIUM | 4.3 | 0.2% | Sep 9, 2025 | SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled function module, which could... |
| CVE-2025-10121 | MEDIUM | 6.3 | 0.2% | Sep 9, 2025 | A flaw has been found in uverif up to 3.2. This affects the function addbatch of the file /admin/kami_list. This manipul... |
| CVE-2025-10117 | MEDIUM | 5.4 | 0.3% | Sep 9, 2025 | A weakness has been identified in SourceCodester Simple To-Do List System 1.0. Impacted is an unknown function of the fi... |
| CVE-2025-43763 | MEDIUM | 6.5 | 0.2% | Sep 9, 2025 | A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP... |
| CVE-2025-58752 | MEDIUM | 5.3 | 0.6% | Sep 8, 2025 | Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files o... |
| CVE-2025-58751 | MEDIUM | 5.3 | 1.2% | Sep 8, 2025 | Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting w... |
| CVE-2025-58452 | MEDIUM | 6.1 | 0.2% | Sep 8, 2025 | WeGIA is a Web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified ... |
| CVE-2025-57815 | MEDIUM | 6.5 | 0.3% | Sep 8, 2025 | Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Admin UI login endpoint relies ... |
| CVE-2025-57766 | MEDIUM | 4.8 | 0.3% | Sep 8, 2025 | Fides is an open-source privacy engineering platform. Prior to version 2.69.1, admin UI user password changes in Fides d... |
| CVE-2025-53838 | MEDIUM | 5.4 | 0.2% | Sep 8, 2025 | LinkAce is a self-hosted archive to collect website links. A stored cross-site scripting (XSS) vulnerability was discove... |
| CVE-2025-43722 | MEDIUM | 6.7 | 0.1% | Sep 8, 2025 | Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper privilege management vulnerability. A high privi... |
| CVE-2025-10099 | MEDIUM | 4.8 | 0.3% | Sep 8, 2025 | A weakness has been identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functiona... |
| CVE-2025-10096 | MEDIUM | 6.5 | 0.3% | Sep 8, 2025 | A vulnerability was determined in SimStudioAI sim up to 1.0.0. This affects an unknown function of the file apps/sim/app... |
| CVE-2025-7709 | MEDIUM | 6.9 | 0.3% | Sep 8, 2025 | An integer overflow exists in the FTS5 https://sqlite.org/fts5.html extension. It occurs when the size of an array of ... |
| CVE-2025-40929 | MEDIUM | 5.6 | 0.4% | Sep 8, 2025 | Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSO... |
| CVE-2025-3212 | MEDIUM | 5.3 | 0.3% | Sep 8, 2025 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge... |
| CVE-2025-40642 | MEDIUM | 5.1 | 0.5% | Sep 8, 2025 | Reflected Cross-Site Scripting (XSS) vulnerability in WebWork, which allows remote attackers to execute arbitrary code t... |
| CVE-2025-40641 | MEDIUM | 5.1 | 0.3% | Sep 8, 2025 | Cross-site Scripting (XSS) vulnerability stored in Multi-Purpose Inventory Management System, consisting of a stored XSS... |
| CVE-2025-58782 | MEDIUM | 6.5 | 1.3% | Sep 8, 2025 | Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now