2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62102 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in apasionados DoFollow Case by Case dofollow-case-by-case allows Cross ... |
| CVE-2025-62100 | MEDIUM | 5.3 | 0.3% | Dec 9, 2025 | Missing Authorization vulnerability in themerain ThemeRain Core themerain-core allows Exploiting Incorrectly Configured ... |
| CVE-2025-62093 | HIGH | 8.5 | 0.3% | Dec 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Image... |
| CVE-2025-62090 | MEDIUM | 6.5 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in Jegstudio Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons g... |
| CVE-2025-62086 | MEDIUM | 5.4 | 0.3% | Dec 9, 2025 | Missing Authorization vulnerability in akazanstev Яндекс Доставка (Boxberry) boxberry allows Exploiting Incorrectly Conf... |
| CVE-2025-62085 | MEDIUM | 5.3 | 0.3% | Dec 9, 2025 | Missing Authorization vulnerability in Bertha AI – Andrew Palmer BERTHA AI bertha-ai-free allows Exploiting Incorrectly ... |
| CVE-2025-62082 | MEDIUM | 6.5 | 0.2% | Dec 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nasir Uddin Generi... |
| CVE-2025-61075 | HIGH | 8.1 | 0.5% | Dec 9, 2025 | Multiple Incorrect Access Control vulnerabilities in adata Software GmbH Mitarbeiterportal 2.15.2.0 allow remote authent... |
| CVE-2025-61074 | MEDIUM | 4.6 | 0.3% | Dec 9, 2025 | A stored Cross Site Scripting (XSS) vulnerability in the bulletin board (SchwarzeBrett) in adata Software GmbH Mitarbeit... |
| CVE-2025-5471 | HIGH | 7.8 | 0.2% | Dec 9, 2025 | Uncontrolled Search Path Element vulnerability in Yandex Telemost on MacOS allows Search Order Hijacking.This issue affe... |
| CVE-2025-5470 | HIGH | 7.3 | 0.1% | Dec 9, 2025 | Uncontrolled Search Path Element vulnerability in Yandex Disk on MacOS allows Search Order Hijacking.This issue affects ... |
| CVE-2025-5469 | HIGH | 7.3 | 0.1% | Dec 9, 2025 | Uncontrolled Search Path Element vulnerability in Yandex Messenger on MacOS allows Search Order Hijacking.This issue aff... |
| CVE-2025-59132 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Badi Jones Duplicate Content Cure duplicate-content-cure allows Cross... |
| CVE-2025-59030 | HIGH | 7.5 | 0.5% | Dec 9, 2025 | An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP. |
| CVE-2025-59029 | MEDIUM | 5.3 | 0.3% | Dec 9, 2025 | An attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the... |
| CVE-2025-49351 | HIGH | 7.1 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Valentin Agachi Create Posts & Terms create-posts-terms allows Stored... |
| CVE-2025-49350 | MEDIUM | 4.3 | 0.3% | Dec 9, 2025 | Missing Authorization vulnerability in marcoingraiti Actionwear products sync actionwear-products-sync allows Exploiting... |
| CVE-2025-49348 | MEDIUM | 5.3 | 0.3% | Dec 9, 2025 | Missing Authorization vulnerability in Hype Hype pico allows Exploiting Incorrectly Configured Access Control Security L... |
| CVE-2025-49347 | HIGH | 7.1 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Jupitercow WP sIFR wp-sifr allows Stored XSS.This issue affects WP sI... |
| CVE-2025-49341 | HIGH | 7.1 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Alex Furr PDF Creator Lite pdf-creator-lite allows Stored XSS.This is... |
| CVE-2025-42928 | CRITICAL | 9.1 | 8.0% | Dec 9, 2025 | Under certain conditions, a high privileged user could exploit a deserialization vulnerability in SAP jConnect to launch... |
| CVE-2025-42904 | MEDIUM | 6.5 | 0.3% | Dec 9, 2025 | Due to an Information Disclosure vulnerability in Application Server ABAP, an authenticated attacker could read unmasked... |
| CVE-2025-42896 | MEDIUM | 5.4 | 0.3% | Dec 9, 2025 | SAP BusinessObjects Business Intelligence Platform lets an unauthenticated remote attacker send crafted requests through... |
| CVE-2025-42891 | MEDIUM | 5.5 | 0.3% | Dec 9, 2025 | Due to a missing authorization check in SAP Enterprise Search for ABAP, an attacker with high privileges may read and ex... |
| CVE-2025-42880 | CRITICAL | 9.9 | 3.9% | Dec 9, 2025 | Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when cal... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now