2025 CVE Vulnerabilities

45,200 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-5741MEDIUM6.9CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could c...
CVE-2025-3905MEDIUM5.4CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists impact...
CVE-2025-3899MEDIUM5.4CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in Cer...
CVE-2025-3117MEDIUM5.4CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists impact...
CVE-2025-3076MEDIUM5.4The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_text...
CVE-2025-5925MEDIUM4.3The Bunny’s Print CSS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2025-42998MEDIUM5.3The security settings in the SAP Business One Integration Framework are not adequately checked, allowing attackers to by...
CVE-2025-42996MEDIUM5.6SAP MDM Server allows an attacker to gain control of existing client sessions and execute certain functions without havi...
CVE-2025-42993MEDIUM6.7Due to a missing authorization check vulnerability in SAP S/4HANA (Enterprise Event Enablement), an attacker with access...
CVE-2025-42991MEDIUM4.3SAP S/4HANA (Bank Account Application) does not perform necessary authorization checks. This allows an authenticated 'ap...
CVE-2025-42988MEDIUM5.3Under certain conditions, SAP Business Objects Business Intelligence Platform allows an unauthenticated attacker to enum...
CVE-2025-42987MEDIUM4.3SAP Manage Processing Rules (For Bank Statement) allows an attacker with basic privileges to edit shared rules of any us...
CVE-2025-42984MEDIUM5.4SAP S/4HANA Manage Central Purchase Contract does not perform necessary authorization checks for an authenticated user. ...
CVE-2025-31325MEDIUM5.8Due to a Cross-Site Scripting vulnerability in SAP NetWeaver (ABAP Keyword Documentation), an unauthenticated attacker c...
CVE-2025-0037MEDIUM6.6In AMD Versal Adaptive SoC devices, the lack of address validation when executing PLM runtime services through the PLM f...
CVE-2025-5899MEDIUM5.3A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected by this ...
CVE-2025-5898MEDIUM5.3A vulnerability classified as critical has been found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected is ...
CVE-2025-49139MEDIUM6.5HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, in the HAX site...
CVE-2025-49138MEDIUM6.5HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, an authenticate...
CVE-2025-49137MEDIUM6.1HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, the application...
CVE-2025-5918MEDIUM6.6A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped in...
CVE-2025-5917MEDIUM5A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when ha...
CVE-2025-5916MEDIUM5.6A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be trigge...
CVE-2025-5915MEDIUM6.6A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the ...
CVE-2025-5891MEDIUM5.3A vulnerability classified as problematic was found in Unitech pm2 up to 6.0.6. This vulnerability affects unknown code ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now