2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-42878 | HIGH | 8.2 | 0.3% | Dec 9, 2025 | SAP Web Dispatcher and ICM may expose internal testing interfaces that are not intended for production. If enabled, unau... |
| CVE-2025-42877 | HIGH | 7.5 | 0.5% | Dec 9, 2025 | SAP Web Dispatcher, Internet Communication Manager (ICM), and SAP Content Server allow an unauthenticated user to exploi... |
| CVE-2025-42876 | HIGH | 7.1 | 0.3% | Dec 9, 2025 | Due to a Missing Authorization Check vulnerability in SAP S/4 HANA Private Cloud (Financials General Ledger), an authent... |
| CVE-2025-42875 | MEDIUM | 6.6 | 0.3% | Dec 9, 2025 | The SAP Internet Communication Framework does not conduct any authentication checks for features that need user identifi... |
| CVE-2025-42874 | HIGH | 7.9 | 0.4% | Dec 9, 2025 | SAP NetWeaver remote service for Xcelsius allows an attacker with network access and high privileges to execute arbitrar... |
| CVE-2025-42873 | MEDIUM | 5.9 | 0.3% | Dec 9, 2025 | SAPUI5 (and OpenUI5) packages use outdated 3rd party libraries with known security vulnerabilities. When markdown-it enc... |
| CVE-2025-42872 | MEDIUM | 6.1 | 0.2% | Dec 9, 2025 | Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, an unauthenticated attacker could ... |
| CVE-2025-41752 | HIGH | 7.1 | 8.2% | Dec 9, 2025 | An XSS vulnerability in pxc_portSfp.php can be used by an unauthenticated remote attacker to trick an authenticated user... |
| CVE-2025-41751 | HIGH | 7.1 | 8.2% | Dec 9, 2025 | An XSS vulnerability in pxc_portCntr.php can be used by an unauthenticated remote attacker to trick an authenticated use... |
| CVE-2025-41750 | HIGH | 7.1 | 8.4% | Dec 9, 2025 | An XSS vulnerability in pxc_PortCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user... |
| CVE-2025-41749 | HIGH | 7.1 | 0.6% | Dec 9, 2025 | An XSS vulnerability in port_util.php can be used by an unauthenticated remote attacker to trick an authenticated user t... |
| CVE-2025-41748 | HIGH | 7.1 | 8.4% | Dec 9, 2025 | An XSS vulnerability in pxc_Dot1xCfg.php can be used by an unauthenticated remote attacker to trick an authenticated use... |
| CVE-2025-41747 | HIGH | 7.1 | 8.2% | Dec 9, 2025 | An XSS vulnerability in pxc_vlanIntfCfg.php can be used by an unauthenticated remote attacker to trick an authenticated ... |
| CVE-2025-41746 | HIGH | 7.1 | 8.2% | Dec 9, 2025 | An XSS vulnerability in pxc_portSecCfg.php can be used by an unauthenticated remote attacker to trick an authenticated u... |
| CVE-2025-41745 | HIGH | 7.1 | 0.5% | Dec 9, 2025 | An XSS vulnerability in pxc_portCntr2.php can be used by an unauthenticated remote attacker to trick an authenticated us... |
| CVE-2025-41697 | MEDIUM | 6.8 | 0.2% | Dec 9, 2025 | An attacker can use an undocumented UART port on the PCB as a side-channel to get root access e.g. with the credentia... |
| CVE-2025-41696 | MEDIUM | 4.6 | 0.2% | Dec 9, 2025 | An attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained ... |
| CVE-2025-41695 | HIGH | 7.1 | 0.6% | Dec 9, 2025 | An XSS vulnerability in dyn_conn.php can be used by an unauthenticated remote attacker to trick an authenticated user to... |
| CVE-2025-41694 | MEDIUM | 6.5 | 0.4% | Dec 9, 2025 | A low privileged remote attacker can run the webshell with an empty command containing whitespace. The server will then ... |
| CVE-2025-41693 | MEDIUM | 4.3 | 0.4% | Dec 9, 2025 | A low privileged remote attacker can use the ssh feature to execute commands directly after login. The process stays ope... |
| CVE-2025-41692 | MEDIUM | 6.8 | 0.3% | Dec 9, 2025 | A high privileged remote attacker with admin privileges for the webUI can brute-force the "root" and "user" passwords of... |
| CVE-2025-40941 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected devices exposes server info... |
| CVE-2025-40940 | MEDIUM | 6.9 | 0.3% | Dec 9, 2025 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application exhibits incons... |
| CVE-2025-40939 | MEDIUM | 5.1 | 0.2% | Dec 9, 2025 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device contains a USB port ... |
| CVE-2025-40938 | CRITICAL | 9.8 | 0.3% | Dec 9, 2025 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive inf... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now