2025 CVE Vulnerabilities
45,200 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5741 | MEDIUM | 6.9 | 0.5% | Jun 10, 2025 | CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could c... |
| CVE-2025-3905 | MEDIUM | 5.4 | 0.2% | Jun 10, 2025 | CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists impact... |
| CVE-2025-3899 | MEDIUM | 5.4 | 0.1% | Jun 10, 2025 | CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in Cer... |
| CVE-2025-3117 | MEDIUM | 5.4 | 0.2% | Jun 10, 2025 | CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists impact... |
| CVE-2025-3076 | MEDIUM | 5.4 | 0.2% | Jun 10, 2025 | The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_text... |
| CVE-2025-5925 | MEDIUM | 4.3 | 0.1% | Jun 10, 2025 | The Bunny’s Print CSS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ... |
| CVE-2025-42998 | MEDIUM | 5.3 | 0.2% | Jun 10, 2025 | The security settings in the SAP Business One Integration Framework are not adequately checked, allowing attackers to by... |
| CVE-2025-42996 | MEDIUM | 5.6 | 0.2% | Jun 10, 2025 | SAP MDM Server allows an attacker to gain control of existing client sessions and execute certain functions without havi... |
| CVE-2025-42993 | MEDIUM | 6.7 | 0.4% | Jun 10, 2025 | Due to a missing authorization check vulnerability in SAP S/4HANA (Enterprise Event Enablement), an attacker with access... |
| CVE-2025-42991 | MEDIUM | 4.3 | 0.2% | Jun 10, 2025 | SAP S/4HANA (Bank Account Application) does not perform necessary authorization checks. This allows an authenticated 'ap... |
| CVE-2025-42988 | MEDIUM | 5.3 | 0.2% | Jun 10, 2025 | Under certain conditions, SAP Business Objects Business Intelligence Platform allows an unauthenticated attacker to enum... |
| CVE-2025-42987 | MEDIUM | 4.3 | 0.2% | Jun 10, 2025 | SAP Manage Processing Rules (For Bank Statement) allows an attacker with basic privileges to edit shared rules of any us... |
| CVE-2025-42984 | MEDIUM | 5.4 | 0.2% | Jun 10, 2025 | SAP S/4HANA Manage Central Purchase Contract does not perform necessary authorization checks for an authenticated user. ... |
| CVE-2025-31325 | MEDIUM | 5.8 | 0.3% | Jun 10, 2025 | Due to a Cross-Site Scripting vulnerability in SAP NetWeaver (ABAP Keyword Documentation), an unauthenticated attacker c... |
| CVE-2025-0037 | MEDIUM | 6.6 | 0.1% | Jun 10, 2025 | In AMD Versal Adaptive SoC devices, the lack of address validation when executing PLM runtime services through the PLM f... |
| CVE-2025-5899 | MEDIUM | 5.3 | 0.1% | Jun 9, 2025 | A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected by this ... |
| CVE-2025-5898 | MEDIUM | 5.3 | 0.1% | Jun 9, 2025 | A vulnerability classified as critical has been found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected is ... |
| CVE-2025-49139 | MEDIUM | 6.5 | 0.3% | Jun 9, 2025 | HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, in the HAX site... |
| CVE-2025-49138 | MEDIUM | 6.5 | 0.4% | Jun 9, 2025 | HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, an authenticate... |
| CVE-2025-49137 | MEDIUM | 6.1 | 0.2% | Jun 9, 2025 | HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, the application... |
| CVE-2025-5918 | MEDIUM | 6.6 | 0.4% | Jun 9, 2025 | A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped in... |
| CVE-2025-5917 | MEDIUM | 5 | 0.2% | Jun 9, 2025 | A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when ha... |
| CVE-2025-5916 | MEDIUM | 5.6 | 0.2% | Jun 9, 2025 | A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be trigge... |
| CVE-2025-5915 | MEDIUM | 6.6 | 0.2% | Jun 9, 2025 | A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the ... |
| CVE-2025-5891 | MEDIUM | 5.3 | 0.6% | Jun 9, 2025 | A vulnerability classified as problematic was found in Unitech pm2 up to 6.0.6. This vulnerability affects unknown code ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now