2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-8081MEDIUM4.9The Elementor plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.30.2 via...
CVE-2025-3892MEDIUM6.7ACAP applications can be executed with elevated privileges, potentially leading to privilege escalation. This vulnerabil...
CVE-2025-30027MEDIUM6.7An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vuln...
CVE-2025-8314MEDIUM6.4The Software Issue Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg param...
CVE-2025-7622MEDIUM5.7During an internal security assessment, a Server-Side Request Forgery (SSRF) vulnerability that allowed an authenticated...
CVE-2025-8690MEDIUM6.4The Simple Responsive Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, an...
CVE-2025-8688MEDIUM6.4The Inline Stock Quotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's stock shortco...
CVE-2025-8685MEDIUM6.4The Wp chart generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpchart shortc...
CVE-2025-8621MEDIUM6.4The Mosaic Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘c’ parameter in all vers...
CVE-2025-8568MEDIUM6.4The GMap Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘h’ parameter in all versio...
CVE-2025-8462MEDIUM6.4The RT Easy Builder – Advanced addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2025-4390MEDIUM5.3The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, ...
CVE-2025-42975MEDIUM6.1SAP NetWeaver Application Server ABAP (BIC Document) allows an unauthenticated attacker to craft a URL link which, when ...
CVE-2025-42949MEDIUM4.9Due to a missing authorization check in the ABAP Platform, an authenticated user with elevated privileges could bypass a...
CVE-2025-42948MEDIUM6.1Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform, an unauthenticated attacker could gene...
CVE-2025-42946MEDIUM6.9Due to directory traversal vulnerability in SAP S/4HANA (Bank Communication Management), an attacker with high privilege...
CVE-2025-42945MEDIUM6.1SAP NetWeaver Application Server ABAP has HTML injection vulnerability. Due to this, an attacker could craft a URL with ...
CVE-2025-42943MEDIUM4.5SAP GUI for Windows may allow the leak of NTML hashes when specific ABAP frontend services are called with UNC paths. Fo...
CVE-2025-42942MEDIUM6.1SAP NetWeaver Application Server for ABAP has cross-site scripting vulnerability. Due to this, an unauthenticated attack...
CVE-2025-42936MEDIUM5.4The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations fo...
CVE-2025-42935MEDIUM4.1The SAP NetWeaver Application Server ABAP and ABAP Platform Internet Communication Manager (ICM) permits authorized user...
CVE-2025-42934MEDIUM4.3SAP S/4HANA Supplier invoice is vulnerable to CRLF Injection. An attacker with user-level privileges can bypass the allo...
CVE-2025-55159MEDIUM5.1slab is a pre-allocated storage for a uniform data type. In version 0.4.10, the get_disjoint_mut method incorrectly chec...
CVE-2025-54992MEDIUM6.9OpenKilda is an open-source OpenFlow controller. Prior to version 1.164.0, an XML external entity (XXE) injection vulner...
CVE-2025-8285MEDIUM5.3Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now