2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-62102MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in apasionados DoFollow Case by Case dofollow-case-by-case allows Cross ...
CVE-2025-62100MEDIUM5.3Missing Authorization vulnerability in themerain ThemeRain Core themerain-core allows Exploiting Incorrectly Configured ...
CVE-2025-62093HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Image...
CVE-2025-62090MEDIUM6.5Missing Authorization vulnerability in Jegstudio Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons g...
CVE-2025-62086MEDIUM5.4Missing Authorization vulnerability in akazanstev Яндекс Доставка (Boxberry) boxberry allows Exploiting Incorrectly Conf...
CVE-2025-62085MEDIUM5.3Missing Authorization vulnerability in Bertha AI – Andrew Palmer BERTHA AI bertha-ai-free allows Exploiting Incorrectly ...
CVE-2025-62082MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nasir Uddin Generi...
CVE-2025-61075HIGH8.1Multiple Incorrect Access Control vulnerabilities in adata Software GmbH Mitarbeiterportal 2.15.2.0 allow remote authent...
CVE-2025-61074MEDIUM4.6A stored Cross Site Scripting (XSS) vulnerability in the bulletin board (SchwarzeBrett) in adata Software GmbH Mitarbeit...
CVE-2025-5471HIGH7.8Uncontrolled Search Path Element vulnerability in Yandex Telemost on MacOS allows Search Order Hijacking.This issue affe...
CVE-2025-5470HIGH7.3Uncontrolled Search Path Element vulnerability in Yandex Disk on MacOS allows Search Order Hijacking.This issue affects ...
CVE-2025-5469HIGH7.3Uncontrolled Search Path Element vulnerability in Yandex Messenger on MacOS allows Search Order Hijacking.This issue aff...
CVE-2025-59132MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Badi Jones Duplicate Content Cure duplicate-content-cure allows Cross...
CVE-2025-59030HIGH7.5An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.
CVE-2025-59029MEDIUM5.3An attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the...
CVE-2025-49351HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Valentin Agachi Create Posts & Terms create-posts-terms allows Stored...
CVE-2025-49350MEDIUM4.3Missing Authorization vulnerability in marcoingraiti Actionwear products sync actionwear-products-sync allows Exploiting...
CVE-2025-49348MEDIUM5.3Missing Authorization vulnerability in Hype Hype pico allows Exploiting Incorrectly Configured Access Control Security L...
CVE-2025-49347HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Jupitercow WP sIFR wp-sifr allows Stored XSS.This issue affects WP sI...
CVE-2025-49341HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Alex Furr PDF Creator Lite pdf-creator-lite allows Stored XSS.This is...
CVE-2025-42928CRITICAL9.1Under certain conditions, a high privileged user could exploit a deserialization vulnerability in SAP jConnect to launch...
CVE-2025-42904MEDIUM6.5Due to an Information Disclosure vulnerability in Application Server ABAP, an authenticated attacker could read unmasked...
CVE-2025-42896MEDIUM5.4SAP BusinessObjects Business Intelligence Platform lets an unauthenticated remote attacker send crafted requests through...
CVE-2025-42891MEDIUM5.5Due to a missing authorization check in SAP Enterprise Search for ABAP, an attacker with high privileges may read and ex...
CVE-2025-42880CRITICAL9.9Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when cal...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now