2025 CVE Vulnerabilities

45,181 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-42979MEDIUM5.6The GuiXT application, which is integrated with SAP GUI for Windows, uses obfuscation algorithms instead of secure symme...
CVE-2025-42974MEDIUM4.3Due to missing authorization check, an attacker authenticated as a non-administrative user could call a remote-enabled f...
CVE-2025-42973MEDIUM5.4Due to a Cross-Site Scripting vulnerability in SAP Data Services Management Console, an authenticated attacker could exp...
CVE-2025-42971MEDIUM4A memory corruption vulnerability exists in SAPCAR allowing an attacker to craft malicious SAPCAR archives. When a high ...
CVE-2025-42970MEDIUM5.8SAPCAR improperly sanitizes the file paths while extracting SAPCAR archives. Due to this, an attacker could craft a mali...
CVE-2025-42969MEDIUM6.1SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject a malicious script ...
CVE-2025-42968MEDIUM4.3SAP NetWeaver allows an authenticated non-administrative user to call the remote-enabled function module which could gra...
CVE-2025-42965MEDIUM4.1SAP CMC Promotion Management allows an authenticated attacker to enumerate internal network systems by submitting crafte...
CVE-2025-42962MEDIUM6.1SAP Business Warehouse (Business Explorer Web) allows an attacker to create a malicious link. If an authenticated user c...
CVE-2025-42961MEDIUM4.9Due to a missing authorization check in SAP NetWeaver Application server for ABAP, an authenticated user with high privi...
CVE-2025-42960MEDIUM4.3SAP Business Warehouse and SAP BW/4HANA BEx Tools allow an authenticated attacker to gain higher access levels than inte...
CVE-2025-31326MEDIUM4.1SAP�BusinessObjects Business�Intelligence Platform (Web Intelligence) is vulnerable to HTML Injection, allowing an attac...
CVE-2025-7153MEDIUM5.4A vulnerability classified as problematic was found in CodeAstro Simple Hospital Management System 1.0. Affected by this...
CVE-2025-7148MEDIUM5.4A vulnerability was found in CodeAstro Simple Hospital Management System 1.0 and classified as problematic. Affected by ...
CVE-2025-7144MEDIUM4.8A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as problematic. This vu...
CVE-2025-7143MEDIUM5.4A vulnerability, which was classified as problematic, was found in SourceCodester Best Salon Management System 1.0. This...
CVE-2025-7142MEDIUM5.4A vulnerability, which was classified as problematic, has been found in SourceCodester Best Salon Management System 1.0....
CVE-2025-53543MEDIUM4.2Kestra is an event-driven orchestration platform. The error message in execution "Overview" tab is vulnerable to stored ...
CVE-2025-53496MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2025-7141MEDIUM5.4A vulnerability classified as problematic was found in SourceCodester Best Salon Management System 1.0. Affected by this...
CVE-2025-7140MEDIUM5.4A vulnerability classified as problematic has been found in SourceCodester Best Salon Management System 1.0. Affected is...
CVE-2025-6044MEDIUM6.1An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the gara...
CVE-2025-53498MEDIUM5.3Insufficient Logging vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Data Leakage Attacks...
CVE-2025-53488MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2025-53478MEDIUM5.4The CheckUser extension’s Special:Investigate interface is vulnerable to reflected XSS due to improper escaping of certa...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now