2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-42878HIGH8.2SAP Web Dispatcher and ICM may expose internal testing interfaces that are not intended for production. If enabled, unau...
CVE-2025-42877HIGH7.5SAP Web Dispatcher, Internet Communication Manager (ICM), and SAP Content Server allow an unauthenticated user to exploi...
CVE-2025-42876HIGH7.1Due to a Missing Authorization Check vulnerability in SAP S/4 HANA Private Cloud (Financials General Ledger), an authent...
CVE-2025-42875MEDIUM6.6The SAP Internet Communication Framework does not conduct any authentication checks for features that need user identifi...
CVE-2025-42874HIGH7.9SAP NetWeaver remote service for Xcelsius allows an attacker with network access and high privileges to execute arbitrar...
CVE-2025-42873MEDIUM5.9SAPUI5 (and OpenUI5) packages use outdated 3rd party libraries with known security vulnerabilities. When markdown-it enc...
CVE-2025-42872MEDIUM6.1Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, an unauthenticated attacker could ...
CVE-2025-41752HIGH7.1An XSS vulnerability in pxc_portSfp.php can be used by an unauthenticated remote attacker to trick an authenticated user...
CVE-2025-41751HIGH7.1An XSS vulnerability in pxc_portCntr.php can be used by an unauthenticated remote attacker to trick an authenticated use...
CVE-2025-41750HIGH7.1An XSS vulnerability in pxc_PortCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user...
CVE-2025-41749HIGH7.1An XSS vulnerability in port_util.php can be used by an unauthenticated remote attacker to trick an authenticated user t...
CVE-2025-41748HIGH7.1An XSS vulnerability in pxc_Dot1xCfg.php can be used by an unauthenticated remote attacker to trick an authenticated use...
CVE-2025-41747HIGH7.1An XSS vulnerability in pxc_vlanIntfCfg.php can be used by an unauthenticated remote attacker to trick an authenticated ...
CVE-2025-41746HIGH7.1An XSS vulnerability in pxc_portSecCfg.php can be used by an unauthenticated remote attacker to trick an authenticated u...
CVE-2025-41745HIGH7.1An XSS vulnerability in pxc_portCntr2.php can be used by an unauthenticated remote attacker to trick an authenticated us...
CVE-2025-41697MEDIUM6.8An attacker can use an undocumented UART port on the PCB as a side-channel to get root access e.g. with the credentia...
CVE-2025-41696MEDIUM4.6An attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained ...
CVE-2025-41695HIGH7.1An XSS vulnerability in dyn_conn.php can be used by an unauthenticated remote attacker to trick an authenticated user to...
CVE-2025-41694MEDIUM6.5A low privileged remote attacker can run the webshell with an empty command containing whitespace. The server will then ...
CVE-2025-41693MEDIUM4.3A low privileged remote attacker can use the ssh feature to execute commands directly after login. The process stays ope...
CVE-2025-41692MEDIUM6.8A high privileged remote attacker with admin privileges for the webUI can brute-force the "root" and "user" passwords of...
CVE-2025-40941MEDIUM4.3A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected devices exposes server info...
CVE-2025-40940MEDIUM6.9A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application exhibits incons...
CVE-2025-40939MEDIUM5.1A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device contains a USB port ...
CVE-2025-40938CRITICAL9.8A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive inf...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now