2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-42919 | MEDIUM | 5.3 | 0.4% | Nov 11, 2025 | Due to an Information Disclosure vulnerability in SAP NetWeaver Application Server Java, internal metadata files could b... |
| CVE-2025-42899 | MEDIUM | 4.3 | 0.2% | Nov 11, 2025 | SAP S4CORE (Manage journal entries) does not perform necessary authorization checks for an authenticated user resulting ... |
| CVE-2025-42897 | MEDIUM | 5.3 | 0.2% | Nov 11, 2025 | Due to information disclosure vulnerability in anonymous API provided by SAP Business One (SLD), an attacker with normal... |
| CVE-2025-42895 | MEDIUM | 6.9 | 0.1% | Nov 11, 2025 | Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a high-privilege locally a... |
| CVE-2025-42894 | MEDIUM | 6.8 | 0.3% | Nov 11, 2025 | Due to a Path Traversal vulnerability in SAP Business Connector, an attacker authenticated as an administrator with adja... |
| CVE-2025-42893 | MEDIUM | 6.1 | 0.2% | Nov 11, 2025 | Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL... |
| CVE-2025-42892 | MEDIUM | 6.8 | 0.9% | Nov 11, 2025 | Due to an OS Command Injection vulnerability in SAP Business Connector, an authenticated attacker with administrative ac... |
| CVE-2025-42890 | CRITICAL | 10 | 0.6% | Nov 11, 2025 | SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended use... |
| CVE-2025-42889 | MEDIUM | 5.4 | 0.2% | Nov 11, 2025 | SAP Starter Solution allows an authenticated attacker to execute crafted database queries, thereby exposing the back-end... |
| CVE-2025-42888 | MEDIUM | 5.5 | 0.1% | Nov 11, 2025 | SAP GUI for Windows may allow a highly privileged user on the affected client PC to locally access sensitive information... |
| CVE-2025-42887 | CRITICAL | 9.9 | 0.5% | Nov 11, 2025 | Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when cal... |
| CVE-2025-42886 | MEDIUM | 6.1 | 0.2% | Nov 11, 2025 | Due to a Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could... |
| CVE-2025-42885 | MEDIUM | 5.8 | 0.3% | Nov 11, 2025 | Due to missing authentication, SAP HANA 2.0 (hdbrss) allows an unauthenticated attacker to call a remote-enabled functio... |
| CVE-2025-42884 | MEDIUM | 6.5 | 0.2% | Nov 11, 2025 | SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject JNDI environment properties or pass a URL u... |
| CVE-2025-42883 | LOW | 2.7 | 0.2% | Nov 11, 2025 | Migration Workbench (DX Workbench) in SAP NetWeaver Application Server for ABAP fails to trigger a malware scan when an ... |
| CVE-2025-42882 | MEDIUM | 4.3 | 0.2% | Nov 11, 2025 | Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with basic ... |
| CVE-2025-31719 | MEDIUM | 5.1 | 0.1% | Nov 11, 2025 | In TEE EcDSA algorithm, there is a possible memory consistency issue. This could lead to generated incorrect signature r... |
| CVE-2025-64529 | MEDIUM | 6.5 | 0.2% | Nov 10, 2025 | SpiceDB is an open source database system for creating and managing security-critical application permissions. In versio... |
| CVE-2025-64522 | HIGH | 7.6 | 0.3% | Nov 10, 2025 | Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where ... |
| CVE-2025-64519 | HIGH | 8.8 | 0.4% | Nov 10, 2025 | TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In versions up to and including ... |
| CVE-2025-63678 | HIGH | 7.2 | 0.4% | Nov 10, 2025 | An authenticated arbitrary file upload vulnerability in the /uploads/ endpoint of CMS Made Simple Foundation File Manage... |
| CVE-2025-12542 | — | — | — | Nov 10, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-11892 | CRITICAL | 9.6 | 0.6% | Nov 10, 2025 | An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allows DOM-based cross... |
| CVE-2025-11578 | HIGH | 7.2 | 0.6% | Nov 10, 2025 | A privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise... |
| CVE-2025-64518 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, valida... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now