2025 CVE Vulnerabilities
45,181 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-42979 | MEDIUM | 5.6 | 0.1% | Jul 8, 2025 | The GuiXT application, which is integrated with SAP GUI for Windows, uses obfuscation algorithms instead of secure symme... |
| CVE-2025-42974 | MEDIUM | 4.3 | 0.2% | Jul 8, 2025 | Due to missing authorization check, an attacker authenticated as a non-administrative user could call a remote-enabled f... |
| CVE-2025-42973 | MEDIUM | 5.4 | 0.2% | Jul 8, 2025 | Due to a Cross-Site Scripting vulnerability in SAP Data Services Management Console, an authenticated attacker could exp... |
| CVE-2025-42971 | MEDIUM | 4 | 0.1% | Jul 8, 2025 | A memory corruption vulnerability exists in SAPCAR allowing an attacker to craft malicious SAPCAR archives. When a high ... |
| CVE-2025-42970 | MEDIUM | 5.8 | 0.3% | Jul 8, 2025 | SAPCAR improperly sanitizes the file paths while extracting SAPCAR archives. Due to this, an attacker could craft a mali... |
| CVE-2025-42969 | MEDIUM | 6.1 | 0.2% | Jul 8, 2025 | SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject a malicious script ... |
| CVE-2025-42968 | MEDIUM | 4.3 | 0.2% | Jul 8, 2025 | SAP NetWeaver allows an authenticated non-administrative user to call the remote-enabled function module which could gra... |
| CVE-2025-42965 | MEDIUM | 4.1 | 0.2% | Jul 8, 2025 | SAP CMC Promotion Management allows an authenticated attacker to enumerate internal network systems by submitting crafte... |
| CVE-2025-42962 | MEDIUM | 6.1 | 0.2% | Jul 8, 2025 | SAP Business Warehouse (Business Explorer Web) allows an attacker to create a malicious link. If an authenticated user c... |
| CVE-2025-42961 | MEDIUM | 4.9 | 0.3% | Jul 8, 2025 | Due to a missing authorization check in SAP NetWeaver Application server for ABAP, an authenticated user with high privi... |
| CVE-2025-42960 | MEDIUM | 4.3 | 0.2% | Jul 8, 2025 | SAP Business Warehouse and SAP BW/4HANA BEx Tools allow an authenticated attacker to gain higher access levels than inte... |
| CVE-2025-31326 | MEDIUM | 4.1 | 0.2% | Jul 8, 2025 | SAP�BusinessObjects Business�Intelligence Platform (Web Intelligence) is vulnerable to HTML Injection, allowing an attac... |
| CVE-2025-7153 | MEDIUM | 5.4 | 0.3% | Jul 8, 2025 | A vulnerability classified as problematic was found in CodeAstro Simple Hospital Management System 1.0. Affected by this... |
| CVE-2025-7148 | MEDIUM | 5.4 | 0.3% | Jul 7, 2025 | A vulnerability was found in CodeAstro Simple Hospital Management System 1.0 and classified as problematic. Affected by ... |
| CVE-2025-7144 | MEDIUM | 4.8 | 0.3% | Jul 7, 2025 | A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as problematic. This vu... |
| CVE-2025-7143 | MEDIUM | 5.4 | 0.3% | Jul 7, 2025 | A vulnerability, which was classified as problematic, was found in SourceCodester Best Salon Management System 1.0. This... |
| CVE-2025-7142 | MEDIUM | 5.4 | 0.3% | Jul 7, 2025 | A vulnerability, which was classified as problematic, has been found in SourceCodester Best Salon Management System 1.0.... |
| CVE-2025-53543 | MEDIUM | 4.2 | 0.2% | Jul 7, 2025 | Kestra is an event-driven orchestration platform. The error message in execution "Overview" tab is vulnerable to stored ... |
| CVE-2025-53496 | MEDIUM | 5.4 | 0.2% | Jul 7, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-7141 | MEDIUM | 5.4 | 0.3% | Jul 7, 2025 | A vulnerability classified as problematic was found in SourceCodester Best Salon Management System 1.0. Affected by this... |
| CVE-2025-7140 | MEDIUM | 5.4 | 0.3% | Jul 7, 2025 | A vulnerability classified as problematic has been found in SourceCodester Best Salon Management System 1.0. Affected is... |
| CVE-2025-6044 | MEDIUM | 6.1 | 0.1% | Jul 7, 2025 | An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the gara... |
| CVE-2025-53498 | MEDIUM | 5.3 | 0.2% | Jul 7, 2025 | Insufficient Logging vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Data Leakage Attacks... |
| CVE-2025-53488 | MEDIUM | 6.1 | 0.2% | Jul 7, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-53478 | MEDIUM | 5.4 | 0.2% | Jul 7, 2025 | The CheckUser extension’s Special:Investigate interface is vulnerable to reflected XSS due to improper escaping of certa... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now