2025 CVE Vulnerabilities

45,223 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-42908MEDIUM5.4Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP, an authenticated ...
CVE-2025-42906MEDIUM5.3SAP Commerce Cloud contains a path traversal vulnerability that may allow users to access web applications such as the A...
CVE-2025-42903MEDIUM4.3A vulnerability in SAP Financial Service Claims Management RFC function ICL_USER_GET_NAME_AND_ADDRESS allows user enumer...
CVE-2025-42902MEDIUM5.3Due to the memory corruption vulnerability in SAP NetWeaver AS ABAP and ABAP Platform, an unauthenticated attacker can s...
CVE-2025-42901MEDIUM5.4SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript payloads which could be e...
CVE-2025-62392MEDIUM6.5SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar...
CVE-2025-62391MEDIUM6.5SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar...
CVE-2025-62390MEDIUM6.5SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar...
CVE-2025-62389MEDIUM6.5SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar...
CVE-2025-62388MEDIUM6.5SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar...
CVE-2025-62387MEDIUM6.5SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar...
CVE-2025-62386MEDIUM6.5SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar...
CVE-2025-62385MEDIUM6.5SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar...
CVE-2025-62384MEDIUM6.5SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar...
CVE-2025-62383MEDIUM6.5SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar...
CVE-2025-62365MEDIUM6.1LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to 25.7.0, there is a reflected-XSS in...
CVE-2025-62363HIGH7.8yt-grabber-tui is a terminal user interface application for downloading videos. In versions before 1.0-rc, the applicati...
CVE-2025-62362MEDIUM6.9gpp-burgerportaal is a Dutch government citizen portal application. In versions before 2.0.3, 3.0.2, and 4.0.1, the name...
CVE-2025-62361MEDIUM6.1WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.0, an Open ...
CVE-2025-62360HIGH8.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.Prior to 3.5.1, a SQL Inj...
CVE-2025-62359MEDIUM6.1WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.0, a Reflec...
CVE-2025-62358MEDIUM6.1WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, the log ...
CVE-2025-62251MEDIUM6.5Liferay Portal 7.3.0 through 7.4.3.119, and Liferay DXP 2023.Q3.1 through 2023.Q3.8, 2023.Q4.0 through 2023.Q4.5, 7.4 GA...
CVE-2025-62179HIGH8.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a SQL In...
CVE-2025-62178MEDIUM5.4WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a Reflec...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now