2025 CVE Vulnerabilities
45,223 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-42908 | MEDIUM | 5.4 | 0.1% | Oct 14, 2025 | Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP, an authenticated ... |
| CVE-2025-42906 | MEDIUM | 5.3 | 0.4% | Oct 14, 2025 | SAP Commerce Cloud contains a path traversal vulnerability that may allow users to access web applications such as the A... |
| CVE-2025-42903 | MEDIUM | 4.3 | 0.3% | Oct 14, 2025 | A vulnerability in SAP Financial Service Claims Management RFC function ICL_USER_GET_NAME_AND_ADDRESS allows user enumer... |
| CVE-2025-42902 | MEDIUM | 5.3 | 0.4% | Oct 14, 2025 | Due to the memory corruption vulnerability in SAP NetWeaver AS ABAP and ABAP Platform, an unauthenticated attacker can s... |
| CVE-2025-42901 | MEDIUM | 5.4 | 0.2% | Oct 14, 2025 | SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript payloads which could be e... |
| CVE-2025-62392 | MEDIUM | 6.5 | 0.8% | Oct 13, 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar... |
| CVE-2025-62391 | MEDIUM | 6.5 | 0.8% | Oct 13, 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar... |
| CVE-2025-62390 | MEDIUM | 6.5 | 1.6% | Oct 13, 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar... |
| CVE-2025-62389 | MEDIUM | 6.5 | 1.6% | Oct 13, 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar... |
| CVE-2025-62388 | MEDIUM | 6.5 | 0.8% | Oct 13, 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar... |
| CVE-2025-62387 | MEDIUM | 6.5 | 1.6% | Oct 13, 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar... |
| CVE-2025-62386 | MEDIUM | 6.5 | 0.8% | Oct 13, 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar... |
| CVE-2025-62385 | MEDIUM | 6.5 | 0.8% | Oct 13, 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar... |
| CVE-2025-62384 | MEDIUM | 6.5 | 0.8% | Oct 13, 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar... |
| CVE-2025-62383 | MEDIUM | 6.5 | 0.8% | Oct 13, 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar... |
| CVE-2025-62365 | MEDIUM | 6.1 | 0.2% | Oct 13, 2025 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to 25.7.0, there is a reflected-XSS in... |
| CVE-2025-62363 | HIGH | 7.8 | 0.2% | Oct 13, 2025 | yt-grabber-tui is a terminal user interface application for downloading videos. In versions before 1.0-rc, the applicati... |
| CVE-2025-62362 | MEDIUM | 6.9 | 0.3% | Oct 13, 2025 | gpp-burgerportaal is a Dutch government citizen portal application. In versions before 2.0.3, 3.0.2, and 4.0.1, the name... |
| CVE-2025-62361 | MEDIUM | 6.1 | 0.2% | Oct 13, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.0, an Open ... |
| CVE-2025-62360 | HIGH | 8.8 | 0.8% | Oct 13, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.Prior to 3.5.1, a SQL Inj... |
| CVE-2025-62359 | MEDIUM | 6.1 | 0.2% | Oct 13, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.0, a Reflec... |
| CVE-2025-62358 | MEDIUM | 6.1 | 0.2% | Oct 13, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, the log ... |
| CVE-2025-62251 | MEDIUM | 6.5 | 0.2% | Oct 13, 2025 | Liferay Portal 7.3.0 through 7.4.3.119, and Liferay DXP 2023.Q3.1 through 2023.Q3.8, 2023.Q4.0 through 2023.Q4.5, 7.4 GA... |
| CVE-2025-62179 | HIGH | 8.8 | 0.4% | Oct 13, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a SQL In... |
| CVE-2025-62178 | MEDIUM | 5.4 | 0.2% | Oct 13, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a Reflec... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now