2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-42919MEDIUM5.3Due to an Information Disclosure vulnerability in SAP NetWeaver Application Server Java, internal metadata files could b...
CVE-2025-42899MEDIUM4.3SAP S4CORE (Manage journal entries) does not perform necessary authorization checks for an authenticated user resulting ...
CVE-2025-42897MEDIUM5.3Due to information disclosure vulnerability in anonymous API provided by SAP Business One (SLD), an attacker with normal...
CVE-2025-42895MEDIUM6.9Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a high-privilege locally a...
CVE-2025-42894MEDIUM6.8Due to a Path Traversal vulnerability in SAP Business Connector, an attacker authenticated as an administrator with adja...
CVE-2025-42893MEDIUM6.1Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL...
CVE-2025-42892MEDIUM6.8Due to an OS Command Injection vulnerability in SAP Business Connector, an authenticated attacker with administrative ac...
CVE-2025-42890CRITICAL10SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended use...
CVE-2025-42889MEDIUM5.4SAP Starter Solution allows an authenticated attacker to execute crafted database queries, thereby exposing the back-end...
CVE-2025-42888MEDIUM5.5SAP GUI for Windows may allow a highly privileged user on the affected client PC to locally access sensitive information...
CVE-2025-42887CRITICAL9.9Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when cal...
CVE-2025-42886MEDIUM6.1Due to a Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could...
CVE-2025-42885MEDIUM5.8Due to missing authentication, SAP HANA 2.0 (hdbrss) allows an unauthenticated attacker to call a remote-enabled functio...
CVE-2025-42884MEDIUM6.5SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject JNDI environment properties or pass a URL u...
CVE-2025-42883LOW2.7Migration Workbench (DX Workbench) in SAP NetWeaver Application Server for ABAP fails to trigger a malware scan when an ...
CVE-2025-42882MEDIUM4.3Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with basic ...
CVE-2025-31719MEDIUM5.1In TEE EcDSA algorithm, there is a possible memory consistency issue. This could lead to generated incorrect signature r...
CVE-2025-64529MEDIUM6.5SpiceDB is an open source database system for creating and managing security-critical application permissions. In versio...
CVE-2025-64522HIGH7.6Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where ...
CVE-2025-64519HIGH8.8TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In versions up to and including ...
CVE-2025-63678HIGH7.2An authenticated arbitrary file upload vulnerability in the /uploads/ endpoint of CMS Made Simple Foundation File Manage...
CVE-2025-12542Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-11892CRITICAL9.6An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allows DOM-based cross...
CVE-2025-11578HIGH7.2A privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise...
CVE-2025-64518HIGH7.5The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, valida...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now