2025 CVE Vulnerabilities

45,224 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-26706MEDIUM5.3Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: fro...
CVE-2025-26704MEDIUM4.3Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: fro...
CVE-2025-26703MEDIUM4.3Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: fro...
CVE-2025-0629MEDIUM4.8The Coronavirus (COVID-19) Notice Message WordPress plugin through 1.1.2 does not sanitise and escape some of its settin...
CVE-2025-26707MEDIUM5.3Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: fro...
CVE-2025-27436MEDIUM4.3The Manage Bank Statements in SAP S/4HANA does not perform required access control checks for an authenticated user to c...
CVE-2025-27433MEDIUM4.3The Manage Bank Statements in SAP S/4HANA allows authenticated attacker to bypass certain functionality restrictions of ...
CVE-2025-27431MEDIUM5.4User management functionality in SAP NetWeaver Application Server Java is vulnerable to Stored Cross-Site Scripting (XSS...
CVE-2025-26660MEDIUM4.3SAP Fiori applications using the posting library fail to properly configure security settings during the setup process, ...
CVE-2025-26659MEDIUM6.1SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to DOM-basedCross-Sit...
CVE-2025-26658MEDIUM6.8The Service Layer in SAP Business One, allows attackers to potentially gain unauthorized access and impersonate other us...
CVE-2025-26656MEDIUM4.3OData Service in Manage Purchasing Info Records does not perform necessary authorization checks for an authenticated use...
CVE-2025-25245MEDIUM6.1SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint tha...
CVE-2025-25244MEDIUM5.7SAP Business Warehouse (Process Chains) allows an attacker to manipulate the process execution due to missing authorizat...
CVE-2025-25242MEDIUM6.1SAP NetWeaver Application Server ABAP allows malicious scripts to be executed in the application, potentially leading to...
CVE-2025-23194MEDIUM5.3SAP NetWeaver Enterprise Portal OBN does not perform proper authentication check for a particular configuration setting....
CVE-2025-23188MEDIUM4.3An authenticated user with low privileges can exploit a missing authorization check in an IBS module of FS-RBD, allowing...
CVE-2025-23185MEDIUM4.1Due to improper error handling in SAP Business Objects Business Intelligence Platform, technical details of the applicat...
CVE-2025-0071MEDIUM4.9SAP Web Dispatcher and Internet Communication Manager allow an attacker with administrative privileges to enable debuggi...
CVE-2025-0062MEDIUM4.7SAP BusinessObjects Business Intelligence Platform allows an attacker to inject JavaScript code in Web Intelligence repo...
CVE-2025-27926MEDIUM5.3In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration files (web.config) cont...
CVE-2025-27924MEDIUM5.4Nintex Automation 5.6 and 5.7 before 5.8 has a stored XSS issue associated with the "Navigate to a URL" action.
CVE-2025-25908MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in tianti v2.3 allows attackers to execute arbitrary web scripts or HT...
CVE-2025-0660MEDIUM4.8Concrete CMS versions 9.0.0 through 9.3.9 are affected by a stored XSS in Folder Function.The "Add Folder" functionality...
CVE-2025-27136MEDIUM5.5LocalS3 is an Amazon S3 mock service for testing and local development. Prior to version 1.21, the LocalS3 service's buc...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now