2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40577 | MEDIUM | 5.3 | 0.2% | May 13, 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices... |
| CVE-2025-40576 | MEDIUM | 5.3 | 0.2% | May 13, 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices... |
| CVE-2025-40575 | MEDIUM | 5.3 | 0.4% | May 13, 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices... |
| CVE-2025-40573 | MEDIUM | 6.7 | 0.2% | May 13, 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices... |
| CVE-2025-40572 | MEDIUM | 6.8 | 0.1% | May 13, 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices... |
| CVE-2025-40555 | MEDIUM | 5.3 | 0.2% | May 13, 2025 | A vulnerability has been identified in APOGEE PXC+TALON TC Series (BACnet) (All versions). Affected devices start sendin... |
| CVE-2025-31929 | MEDIUM | 4.2 | 0.2% | May 13, 2025 | A vulnerability has been identified in IEC 1Ph 7.4kW Child socket (8EM1310-2EH04-0GA0) (All versions), IEC 1Ph 7.4kW Chi... |
| CVE-2025-3916 | MEDIUM | 4.6 | 0.2% | May 13, 2025 | CWE-121: Stack-based Buffer Overflow vulnerability exists that could cause local attackers being able to exploit these i... |
| CVE-2025-4339 | MEDIUM | 4.3 | 0.4% | May 13, 2025 | The TheGem theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t... |
| CVE-2025-3107 | MEDIUM | 6.5 | 0.3% | May 13, 2025 | The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby' parameter in all versio... |
| CVE-2025-43009 | MEDIUM | 6.3 | 0.2% | May 13, 2025 | SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing a... |
| CVE-2025-43008 | MEDIUM | 5.8 | 0.3% | May 13, 2025 | Due to missing authorization check, an unauthorized user can view the files of other company. This might lead to disclos... |
| CVE-2025-43007 | MEDIUM | 6.3 | 0.2% | May 13, 2025 | SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing a... |
| CVE-2025-43006 | MEDIUM | 6.1 | 0.3% | May 13, 2025 | SAP Supplier Relationship Management (Master Data Management Catalogue) allows an unauthenticated attacker to execute ma... |
| CVE-2025-43005 | MEDIUM | 4.3 | 0.2% | May 13, 2025 | SAP GUI for Windows allows an unauthenticated attacker to exploit insecure obfuscation algorithms used by the GuiXT appl... |
| CVE-2025-43004 | MEDIUM | 5.3 | 0.3% | May 13, 2025 | Due to a security misconfiguration vulnerability, customers can develop Production Operator Dashboards (PODs) that enabl... |
| CVE-2025-43003 | MEDIUM | 6.4 | 0.3% | May 13, 2025 | SAP S/4 HANA allows an authenticated attacker with user privileges to configure a field not intended for their access an... |
| CVE-2025-43002 | MEDIUM | 4.3 | 0.3% | May 13, 2025 | SAP S4CORE OData meta-data property allows an authenticated attacker to access restricted information due to missing aut... |
| CVE-2025-42997 | MEDIUM | 6.6 | 0.2% | May 13, 2025 | Under certain conditions, SAP Gateway Client allows a high-privileged user to access restricted information beyond the s... |
| CVE-2025-31329 | MEDIUM | 6.2 | 0.3% | May 13, 2025 | SAP NetWeaver is vulnerable to an Information Disclosure vulnerability caused by the injection of malicious instructions... |
| CVE-2025-30011 | MEDIUM | 5.3 | 0.3% | May 13, 2025 | The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within th... |
| CVE-2025-30010 | MEDIUM | 6.1 | 0.3% | May 13, 2025 | The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within th... |
| CVE-2025-30009 | MEDIUM | 6.1 | 0.3% | May 13, 2025 | he Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the... |
| CVE-2025-26662 | MEDIUM | 4.4 | 0.2% | May 13, 2025 | The Data Services Management Console does not sufficiently encode user-controlled inputs, allowing an attacker to inject... |
| CVE-2025-46825 | MEDIUM | 5.4 | 0.3% | May 12, 2025 | Kanboard is project management software that focuses on the Kanban methodology. Versions 1.2.26 through 1.2.44 have a St... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now