2025 CVE Vulnerabilities

45,213 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-22009MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: regulator: dummy: force synchronous probing Someti...
CVE-2025-22008MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: regulator: check that dummy regulator has been prob...
CVE-2025-31333MEDIUM4.3SAP S4CORE OData meta-data property is vulnerable to data tampering, due to which entity set could be externally modifie...
CVE-2025-31331MEDIUM4.3SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would ...
CVE-2025-30017MEDIUM4.4Due to a missing authorization check, an authenticated attacker could upload a file as a template for solution documenta...
CVE-2025-30015MEDIUM4.1Due to incorrect memory address handling in ABAP SQL of SAP NetWeaver and ABAP Platform (Application Server ABAP), an au...
CVE-2025-30013MEDIUM6.7SAP ERP BW Business Content is vulnerable to OS Command Injection through certain function modules. These function modul...
CVE-2025-2882MEDIUM5.3The GreenPay(tm) by Green.Money plugin for WordPress is vulnerable to Sensitive Information Exposure in versions between...
CVE-2025-27437MEDIUM4.3A Missing Authorization Check vulnerability exists in the Virus Scanner Interface of SAP NetWeaver Application Server AB...
CVE-2025-27435MEDIUM4.2Under specific conditions and prerequisites, an unauthenticated attacker could access customer coupon codes exposed in t...
CVE-2025-26657MEDIUM5.3SAP KMC WPC allows an unauthenticated attacker to remotely retrieve usernames by a simple parameter query which could ex...
CVE-2025-26654MEDIUM6.8SAP Commerce Cloud (Public Cloud) does not allow to disable unencrypted HTTP (port 80) entirely, but instead allows a re...
CVE-2025-26653MEDIUM4.7SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site ...
CVE-2025-3430MEDIUM4.9The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'printer_text' parameter in all versions up...
CVE-2025-3429MEDIUM4.9The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'material_text' parameter in all versions u...
CVE-2025-3428MEDIUM4.9The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'coating_text' parameter in all versions up...
CVE-2025-3427MEDIUM4.9The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'infill_text' parameter in all versions up ...
CVE-2025-3412MEDIUM6.3A vulnerability, which was classified as critical, was found in mymagicpower AIAS 20250308. Affected is an unknown funct...
CVE-2025-0361MEDIUM5.3During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Dev...
CVE-2025-3411MEDIUM6.3A vulnerability, which was classified as critical, has been found in mymagicpower AIAS 20250308. This issue affects some...
CVE-2025-20951MEDIUM5.5Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows loc...
CVE-2025-20950MEDIUM5.5Use of implicit intent for sensitive communication in SamsungNotes prior to version 4.4.26.45 allows local attackers to ...
CVE-2025-20947MEDIUM5.5Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows lo...
CVE-2025-20945MEDIUM6.2Improper access control in Galaxy Watch prior to SMR Apr-2025 Release 1 allows local attackers to access sensitive infor...
CVE-2025-20943MEDIUM4.4Out-of-bounds write in secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to cause memory ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now