2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-1176MEDIUM5A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function _bfd_elf_gc_m...
CVE-2025-1211MEDIUM6.5Versions of the package hackney before 1.21.0 are vulnerable to Server-side Request Forgery (SSRF) due to improper parsi...
CVE-2025-1174MEDIUM4.8A vulnerability has been found in 1000 Projects Bookstore Management System 1.0 and classified as problematic. This vuln...
CVE-2025-1171MEDIUM6.1A vulnerability classified as problematic was found in code-projects Real Estate Property Management System 1.0. Affecte...
CVE-2025-1145MEDIUM6.1NetVision Information ISOinsight has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote att...
CVE-2025-1170MEDIUM5.4A vulnerability classified as problematic has been found in code-projects Real Estate Property Management System 1.0. Af...
CVE-2025-1169MEDIUM6.1A vulnerability was found in SourceCodester Image Compressor Tool 1.0. It has been rated as problematic. This issue affe...
CVE-2025-25241MEDIUM5.4Due to a missing authorization check, an attacker who is logged in to application can view/ delete �My Overtime Requests...
CVE-2025-24875MEDIUM6.8SAP Commerce, by default, sets certain cookies with the SameSite attribute configured to None (SameSite=None). This incl...
CVE-2025-24874MEDIUM6.8SAP Commerce (Backoffice) uses the deprecated X-FRAME-OPTIONS header to protect against clickjacking. While this protect...
CVE-2025-24872MEDIUM4.3The ABAP Build Framework in SAP ABAP Platform allows an authenticated attacker to gain unauthorized access to a specific...
CVE-2025-24870MEDIUM6SAP GUI for Windows & RFC service credentials are incorrectly stored in the memory of the program allowing an unauthenti...
CVE-2025-24869MEDIUM4.3SAP NetWeaver Application Server Java allows an attacker to access an endpoint that can disclose information about deplo...
CVE-2025-24867MEDIUM6.1SAP BusinessObjects Platform (BI Launchpad) does not sufficiently handle user input, resulting in Cross-Site Scripting (...
CVE-2025-23190MEDIUM4.3Due to missing authorization check, an authenticated attacker could call a remote-enabled function module which allows t...
CVE-2025-23189MEDIUM4.3Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an authenticated attacker cou...
CVE-2025-23187MEDIUM5.3Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an unauthenticated attacker c...
CVE-2025-0064MEDIUM6.5Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intelligence platform allo...
CVE-2025-0054MEDIUM5.4SAP NetWeaver Application Server Java does not sufficiently handle user input, resulting in a stored cross-site scriptin...
CVE-2025-1164MEDIUM5.5A vulnerability, which was classified as problematic, has been found in code-projects Police FIR Record Management Syste...
CVE-2025-25194MEDIUM4Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on a...
CVE-2025-25193MEDIUM5.5Netty, an asynchronous, event-driven network application framework, has a vulnerability in versions up to and including ...
CVE-2025-25190MEDIUM5.5The ZOO-Project is an open source processing platform. The ZOO-Project Web Processing Service (WPS) Server contains a Cr...
CVE-2025-25189MEDIUM5.5The ZOO-Project is an open source processing platform. A reflected Cross-Site Scripting vulnerability exists in the ZOO-...
CVE-2025-1159MEDIUM5.4A vulnerability was found in CampCodes School Management Software 1.0. It has been declared as problematic. Affected by ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now