2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8081 | MEDIUM | 4.9 | 0.5% | Aug 12, 2025 | The Elementor plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.30.2 via... |
| CVE-2025-3892 | MEDIUM | 6.7 | 0.1% | Aug 12, 2025 | ACAP applications can be executed with elevated privileges, potentially leading to privilege escalation. This vulnerabil... |
| CVE-2025-30027 | MEDIUM | 6.7 | 0.1% | Aug 12, 2025 | An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vuln... |
| CVE-2025-8314 | MEDIUM | 6.4 | 0.2% | Aug 12, 2025 | The Software Issue Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg param... |
| CVE-2025-7622 | MEDIUM | 5.7 | 0.2% | Aug 12, 2025 | During an internal security assessment, a Server-Side Request Forgery (SSRF) vulnerability that allowed an authenticated... |
| CVE-2025-8690 | MEDIUM | 6.4 | 0.2% | Aug 12, 2025 | The Simple Responsive Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, an... |
| CVE-2025-8688 | MEDIUM | 6.4 | 0.2% | Aug 12, 2025 | The Inline Stock Quotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's stock shortco... |
| CVE-2025-8685 | MEDIUM | 6.4 | 0.2% | Aug 12, 2025 | The Wp chart generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpchart shortc... |
| CVE-2025-8621 | MEDIUM | 6.4 | 0.2% | Aug 12, 2025 | The Mosaic Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘c’ parameter in all vers... |
| CVE-2025-8568 | MEDIUM | 6.4 | 0.2% | Aug 12, 2025 | The GMap Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘h’ parameter in all versio... |
| CVE-2025-8462 | MEDIUM | 6.4 | 0.2% | Aug 12, 2025 | The RT Easy Builder – Advanced addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi... |
| CVE-2025-4390 | MEDIUM | 5.3 | 0.3% | Aug 12, 2025 | The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, ... |
| CVE-2025-42975 | MEDIUM | 6.1 | 0.2% | Aug 12, 2025 | SAP NetWeaver Application Server ABAP (BIC Document) allows an unauthenticated attacker to craft a URL link which, when ... |
| CVE-2025-42949 | MEDIUM | 4.9 | 0.3% | Aug 12, 2025 | Due to a missing authorization check in the ABAP Platform, an authenticated user with elevated privileges could bypass a... |
| CVE-2025-42948 | MEDIUM | 6.1 | 0.2% | Aug 12, 2025 | Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform, an unauthenticated attacker could gene... |
| CVE-2025-42946 | MEDIUM | 6.9 | 0.9% | Aug 12, 2025 | Due to directory traversal vulnerability in SAP S/4HANA (Bank Communication Management), an attacker with high privilege... |
| CVE-2025-42945 | MEDIUM | 6.1 | 0.2% | Aug 12, 2025 | SAP NetWeaver Application Server ABAP has HTML injection vulnerability. Due to this, an attacker could craft a URL with ... |
| CVE-2025-42943 | MEDIUM | 4.5 | 0.3% | Aug 12, 2025 | SAP GUI for Windows may allow the leak of NTML hashes when specific ABAP frontend services are called with UNC paths. Fo... |
| CVE-2025-42942 | MEDIUM | 6.1 | 0.2% | Aug 12, 2025 | SAP NetWeaver Application Server for ABAP has cross-site scripting vulnerability. Due to this, an unauthenticated attack... |
| CVE-2025-42936 | MEDIUM | 5.4 | 0.2% | Aug 12, 2025 | The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations fo... |
| CVE-2025-42935 | MEDIUM | 4.1 | 0.1% | Aug 12, 2025 | The SAP NetWeaver Application Server ABAP and ABAP Platform Internet Communication Manager (ICM) permits authorized user... |
| CVE-2025-42934 | MEDIUM | 4.3 | 0.2% | Aug 12, 2025 | SAP S/4HANA Supplier invoice is vulnerable to CRLF Injection. An attacker with user-level privileges can bypass the allo... |
| CVE-2025-55159 | MEDIUM | 5.1 | 0.2% | Aug 11, 2025 | slab is a pre-allocated storage for a uniform data type. In version 0.4.10, the get_disjoint_mut method incorrectly chec... |
| CVE-2025-54992 | MEDIUM | 6.9 | 0.4% | Aug 11, 2025 | OpenKilda is an open-source OpenFlow controller. Prior to version 1.164.0, an XML external entity (XXE) injection vulner... |
| CVE-2025-8285 | MEDIUM | 5.3 | 0.2% | Aug 11, 2025 | Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now