2025 CVE Vulnerabilities
45,213 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-22009 | MEDIUM | 5.5 | 0.2% | Apr 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: regulator: dummy: force synchronous probing Someti... |
| CVE-2025-22008 | MEDIUM | 5.5 | 0.2% | Apr 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: regulator: check that dummy regulator has been prob... |
| CVE-2025-31333 | MEDIUM | 4.3 | 0.2% | Apr 8, 2025 | SAP S4CORE OData meta-data property is vulnerable to data tampering, due to which entity set could be externally modifie... |
| CVE-2025-31331 | MEDIUM | 4.3 | 0.3% | Apr 8, 2025 | SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would ... |
| CVE-2025-30017 | MEDIUM | 4.4 | 0.1% | Apr 8, 2025 | Due to a missing authorization check, an authenticated attacker could upload a file as a template for solution documenta... |
| CVE-2025-30015 | MEDIUM | 4.1 | 0.2% | Apr 8, 2025 | Due to incorrect memory address handling in ABAP SQL of SAP NetWeaver and ABAP Platform (Application Server ABAP), an au... |
| CVE-2025-30013 | MEDIUM | 6.7 | 0.8% | Apr 8, 2025 | SAP ERP BW Business Content is vulnerable to OS Command Injection through certain function modules. These function modul... |
| CVE-2025-2882 | MEDIUM | 5.3 | 0.3% | Apr 8, 2025 | The GreenPay(tm) by Green.Money plugin for WordPress is vulnerable to Sensitive Information Exposure in versions between... |
| CVE-2025-27437 | MEDIUM | 4.3 | 0.2% | Apr 8, 2025 | A Missing Authorization Check vulnerability exists in the Virus Scanner Interface of SAP NetWeaver Application Server AB... |
| CVE-2025-27435 | MEDIUM | 4.2 | 0.2% | Apr 8, 2025 | Under specific conditions and prerequisites, an unauthenticated attacker could access customer coupon codes exposed in t... |
| CVE-2025-26657 | MEDIUM | 5.3 | 0.3% | Apr 8, 2025 | SAP KMC WPC allows an unauthenticated attacker to remotely retrieve usernames by a simple parameter query which could ex... |
| CVE-2025-26654 | MEDIUM | 6.8 | 0.1% | Apr 8, 2025 | SAP Commerce Cloud (Public Cloud) does not allow to disable unencrypted HTTP (port 80) entirely, but instead allows a re... |
| CVE-2025-26653 | MEDIUM | 4.7 | 0.2% | Apr 8, 2025 | SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site ... |
| CVE-2025-3430 | MEDIUM | 4.9 | 0.3% | Apr 8, 2025 | The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'printer_text' parameter in all versions up... |
| CVE-2025-3429 | MEDIUM | 4.9 | 0.3% | Apr 8, 2025 | The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'material_text' parameter in all versions u... |
| CVE-2025-3428 | MEDIUM | 4.9 | 0.3% | Apr 8, 2025 | The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'coating_text' parameter in all versions up... |
| CVE-2025-3427 | MEDIUM | 4.9 | 0.3% | Apr 8, 2025 | The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'infill_text' parameter in all versions up ... |
| CVE-2025-3412 | MEDIUM | 6.3 | 0.4% | Apr 8, 2025 | A vulnerability, which was classified as critical, was found in mymagicpower AIAS 20250308. Affected is an unknown funct... |
| CVE-2025-0361 | MEDIUM | 5.3 | 0.3% | Apr 8, 2025 | During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Dev... |
| CVE-2025-3411 | MEDIUM | 6.3 | 0.4% | Apr 8, 2025 | A vulnerability, which was classified as critical, has been found in mymagicpower AIAS 20250308. This issue affects some... |
| CVE-2025-20951 | MEDIUM | 5.5 | 0.1% | Apr 8, 2025 | Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows loc... |
| CVE-2025-20950 | MEDIUM | 5.5 | 0.1% | Apr 8, 2025 | Use of implicit intent for sensitive communication in SamsungNotes prior to version 4.4.26.45 allows local attackers to ... |
| CVE-2025-20947 | MEDIUM | 5.5 | 0.1% | Apr 8, 2025 | Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows lo... |
| CVE-2025-20945 | MEDIUM | 6.2 | 0.1% | Apr 8, 2025 | Improper access control in Galaxy Watch prior to SMR Apr-2025 Release 1 allows local attackers to access sensitive infor... |
| CVE-2025-20943 | MEDIUM | 4.4 | 0.1% | Apr 8, 2025 | Out-of-bounds write in secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to cause memory ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now