2025 CVE Vulnerabilities
45,224 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-26706 | MEDIUM | 5.3 | 0.2% | Mar 11, 2025 | Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: fro... |
| CVE-2025-26704 | MEDIUM | 4.3 | 0.2% | Mar 11, 2025 | Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: fro... |
| CVE-2025-26703 | MEDIUM | 4.3 | 0.2% | Mar 11, 2025 | Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: fro... |
| CVE-2025-0629 | MEDIUM | 4.8 | 0.2% | Mar 11, 2025 | The Coronavirus (COVID-19) Notice Message WordPress plugin through 1.1.2 does not sanitise and escape some of its settin... |
| CVE-2025-26707 | MEDIUM | 5.3 | 0.3% | Mar 11, 2025 | Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: fro... |
| CVE-2025-27436 | MEDIUM | 4.3 | 0.2% | Mar 11, 2025 | The Manage Bank Statements in SAP S/4HANA does not perform required access control checks for an authenticated user to c... |
| CVE-2025-27433 | MEDIUM | 4.3 | 0.3% | Mar 11, 2025 | The Manage Bank Statements in SAP S/4HANA allows authenticated attacker to bypass certain functionality restrictions of ... |
| CVE-2025-27431 | MEDIUM | 5.4 | 0.2% | Mar 11, 2025 | User management functionality in SAP NetWeaver Application Server Java is vulnerable to Stored Cross-Site Scripting (XSS... |
| CVE-2025-26660 | MEDIUM | 4.3 | 0.3% | Mar 11, 2025 | SAP Fiori applications using the posting library fail to properly configure security settings during the setup process, ... |
| CVE-2025-26659 | MEDIUM | 6.1 | 0.2% | Mar 11, 2025 | SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to DOM-basedCross-Sit... |
| CVE-2025-26658 | MEDIUM | 6.8 | 0.3% | Mar 11, 2025 | The Service Layer in SAP Business One, allows attackers to potentially gain unauthorized access and impersonate other us... |
| CVE-2025-26656 | MEDIUM | 4.3 | 0.2% | Mar 11, 2025 | OData Service in Manage Purchasing Info Records does not perform necessary authorization checks for an authenticated use... |
| CVE-2025-25245 | MEDIUM | 6.1 | 0.2% | Mar 11, 2025 | SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint tha... |
| CVE-2025-25244 | MEDIUM | 5.7 | 0.2% | Mar 11, 2025 | SAP Business Warehouse (Process Chains) allows an attacker to manipulate the process execution due to missing authorizat... |
| CVE-2025-25242 | MEDIUM | 6.1 | 0.2% | Mar 11, 2025 | SAP NetWeaver Application Server ABAP allows malicious scripts to be executed in the application, potentially leading to... |
| CVE-2025-23194 | MEDIUM | 5.3 | 0.3% | Mar 11, 2025 | SAP NetWeaver Enterprise Portal OBN does not perform proper authentication check for a particular configuration setting.... |
| CVE-2025-23188 | MEDIUM | 4.3 | 0.2% | Mar 11, 2025 | An authenticated user with low privileges can exploit a missing authorization check in an IBS module of FS-RBD, allowing... |
| CVE-2025-23185 | MEDIUM | 4.1 | 0.3% | Mar 11, 2025 | Due to improper error handling in SAP Business Objects Business Intelligence Platform, technical details of the applicat... |
| CVE-2025-0071 | MEDIUM | 4.9 | 0.4% | Mar 11, 2025 | SAP Web Dispatcher and Internet Communication Manager allow an attacker with administrative privileges to enable debuggi... |
| CVE-2025-0062 | MEDIUM | 4.7 | 0.3% | Mar 11, 2025 | SAP BusinessObjects Business Intelligence Platform allows an attacker to inject JavaScript code in Web Intelligence repo... |
| CVE-2025-27926 | MEDIUM | 5.3 | 0.3% | Mar 10, 2025 | In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration files (web.config) cont... |
| CVE-2025-27924 | MEDIUM | 5.4 | 0.2% | Mar 10, 2025 | Nintex Automation 5.6 and 5.7 before 5.8 has a stored XSS issue associated with the "Navigate to a URL" action. |
| CVE-2025-25908 | MEDIUM | 5.4 | 0.2% | Mar 10, 2025 | A stored cross-site scripting (XSS) vulnerability in tianti v2.3 allows attackers to execute arbitrary web scripts or HT... |
| CVE-2025-0660 | MEDIUM | 4.8 | 0.3% | Mar 10, 2025 | Concrete CMS versions 9.0.0 through 9.3.9 are affected by a stored XSS in Folder Function.The "Add Folder" functionality... |
| CVE-2025-27136 | MEDIUM | 5.5 | 0.5% | Mar 10, 2025 | LocalS3 is an Amazon S3 mock service for testing and local development. Prior to version 1.21, the LocalS3 service's buc... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now