2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-40577MEDIUM5.3A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices...
CVE-2025-40576MEDIUM5.3A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices...
CVE-2025-40575MEDIUM5.3A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices...
CVE-2025-40573MEDIUM6.7A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices...
CVE-2025-40572MEDIUM6.8A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices...
CVE-2025-40555MEDIUM5.3A vulnerability has been identified in APOGEE PXC+TALON TC Series (BACnet) (All versions). Affected devices start sendin...
CVE-2025-31929MEDIUM4.2A vulnerability has been identified in IEC 1Ph 7.4kW Child socket (8EM1310-2EH04-0GA0) (All versions), IEC 1Ph 7.4kW Chi...
CVE-2025-3916MEDIUM4.6CWE-121: Stack-based Buffer Overflow vulnerability exists that could cause local attackers being able to exploit these i...
CVE-2025-4339MEDIUM4.3The TheGem theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t...
CVE-2025-3107MEDIUM6.5The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby' parameter in all versio...
CVE-2025-43009MEDIUM6.3SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing a...
CVE-2025-43008MEDIUM5.8Due to missing authorization check, an unauthorized user can view the files of other company. This might lead to disclos...
CVE-2025-43007MEDIUM6.3SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing a...
CVE-2025-43006MEDIUM6.1SAP Supplier Relationship Management (Master Data Management Catalogue) allows an unauthenticated attacker to execute ma...
CVE-2025-43005MEDIUM4.3SAP GUI for Windows allows an unauthenticated attacker to exploit insecure obfuscation algorithms used by the GuiXT appl...
CVE-2025-43004MEDIUM5.3Due to a security misconfiguration vulnerability, customers can develop Production Operator Dashboards (PODs) that enabl...
CVE-2025-43003MEDIUM6.4SAP S/4 HANA allows an authenticated attacker with user privileges to configure a field not intended for their access an...
CVE-2025-43002MEDIUM4.3SAP S4CORE OData meta-data property allows an authenticated attacker to access restricted information due to missing aut...
CVE-2025-42997MEDIUM6.6Under certain conditions, SAP Gateway Client allows a high-privileged user to access restricted information beyond the s...
CVE-2025-31329MEDIUM6.2SAP NetWeaver is vulnerable to an Information Disclosure vulnerability caused by the injection of malicious instructions...
CVE-2025-30011MEDIUM5.3The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within th...
CVE-2025-30010MEDIUM6.1The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within th...
CVE-2025-30009MEDIUM6.1he Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the...
CVE-2025-26662MEDIUM4.4The Data Services Management Console does not sufficiently encode user-controlled inputs, allowing an attacker to inject...
CVE-2025-46825MEDIUM5.4Kanboard is project management software that focuses on the Kanban methodology. Versions 1.2.26 through 1.2.44 have a St...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now