2025 CVE Vulnerabilities
45,251 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40795 | CRITICAL | 9.8 | 0.7% | Sep 9, 2025 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC... |
| CVE-2025-40757 | MEDIUM | 6.3 | 0.3% | Sep 9, 2025 | A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All v... |
| CVE-2025-40594 | CRITICAL | 9.8 | 0.2% | Sep 9, 2025 | A vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS S200 V6.4 (All versions < ... |
| CVE-2025-10134 | CRITICAL | 9.1 | 0.5% | Sep 9, 2025 | The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insuffi... |
| CVE-2025-9542 | MEDIUM | 5.4 | 0.2% | Sep 9, 2025 | The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP... |
| CVE-2025-9539 | HIGH | 8 | 0.4% | Sep 9, 2025 | The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP... |
| CVE-2025-9111 | LOW | 3.5 | 0.2% | Sep 9, 2025 | The AI ChatBot for WordPress WordPress plugin before 7.1.0 does not sanitise and escape some of its settings, which cou... |
| CVE-2025-9061 | MEDIUM | 6.4 | 0.2% | Sep 9, 2025 | The Wilmer Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and ... |
| CVE-2025-9058 | MEDIUM | 6.4 | 0.2% | Sep 9, 2025 | The Mikado Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and ... |
| CVE-2025-8889 | LOW | 3.8 | 0.3% | Sep 9, 2025 | The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege u... |
| CVE-2025-9489 | MEDIUM | 5 | 0.3% | Sep 9, 2025 | The The WP-Members Membership Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions... |
| CVE-2025-43777 | MEDIUM | 5.3 | 0.2% | Sep 9, 2025 | Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024... |
| CVE-2025-10123 | CRITICAL | 9.8 | 4.0% | Sep 9, 2025 | A vulnerability was determined in D-Link DIR-823X up to 250416. Affected by this vulnerability is the function sub_41502... |
| CVE-2025-10122 | HIGH | 7.2 | 0.3% | Sep 9, 2025 | A vulnerability was found in Maccms10 2025.1000.4050. Affected is the function rep of the file application/admin/control... |
| CVE-2025-43778 | MEDIUM | 6.1 | 0.2% | Sep 9, 2025 | A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 th... |
| CVE-2025-42958 | CRITICAL | 9.1 | 0.7% | Sep 9, 2025 | Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the application allows high priv... |
| CVE-2025-42944 | CRITICAL | 10 | 2.9% | Sep 9, 2025 | Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through th... |
| CVE-2025-42938 | MEDIUM | 6.1 | 0.2% | Sep 9, 2025 | Due to a Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform, an unauthenticated attacker could ... |
| CVE-2025-42933 | HIGH | 8.8 | 0.3% | Sep 9, 2025 | When a user logs in via SAP Business One native client, the SLD backend service fails to enforce proper encryption of ce... |
| CVE-2025-42930 | MEDIUM | 6.5 | 0.3% | Sep 9, 2025 | SAP Business Planning and Consolidation allows an authenticated standard user to call a function module by crafting spec... |
| CVE-2025-42929 | HIGH | 8.1 | 0.2% | Sep 9, 2025 | Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbi... |
| CVE-2025-42927 | LOW | 3.4 | 0.1% | Sep 9, 2025 | SAP NetWeaver AS Java application uses Adobe Document Service, installed with a vulnerable version of OpenSSL.Successful... |
| CVE-2025-42926 | MEDIUM | 5.3 | 0.3% | Sep 9, 2025 | SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access inter... |
| CVE-2025-42925 | MEDIUM | 4.3 | 0.2% | Sep 9, 2025 | Due to the lack of randomness in assigning Object Identifiers in the SAP NetWeaver AS JAVA IIOP service, an authenticate... |
| CVE-2025-42923 | MEDIUM | 4.3 | 0.1% | Sep 9, 2025 | Due to insufficient CSRF protection in SAP Fiori App Manage Work Center Groups, an authenticated user could be tricked b... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now