2025 CVE Vulnerabilities

45,251 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-40795CRITICAL9.8A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC...
CVE-2025-40757MEDIUM6.3A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All v...
CVE-2025-40594CRITICAL9.8A vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS S200 V6.4 (All versions < ...
CVE-2025-10134CRITICAL9.1The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insuffi...
CVE-2025-9542MEDIUM5.4The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP...
CVE-2025-9539HIGH8The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP...
CVE-2025-9111LOW3.5The AI ChatBot for WordPress WordPress plugin before 7.1.0 does not sanitise and escape some of its settings, which cou...
CVE-2025-9061MEDIUM6.4The Wilmer Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and ...
CVE-2025-9058MEDIUM6.4The Mikado Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and ...
CVE-2025-8889LOW3.8The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege u...
CVE-2025-9489MEDIUM5The The WP-Members Membership Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions...
CVE-2025-43777MEDIUM5.3Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024...
CVE-2025-10123CRITICAL9.8A vulnerability was determined in D-Link DIR-823X up to 250416. Affected by this vulnerability is the function sub_41502...
CVE-2025-10122HIGH7.2A vulnerability was found in Maccms10 2025.1000.4050. Affected is the function rep of the file application/admin/control...
CVE-2025-43778MEDIUM6.1A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 th...
CVE-2025-42958CRITICAL9.1Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the application allows high priv...
CVE-2025-42944CRITICAL10Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through th...
CVE-2025-42938MEDIUM6.1Due to a Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform, an unauthenticated attacker could ...
CVE-2025-42933HIGH8.8When a user logs in via SAP Business One native client, the SLD backend service fails to enforce proper encryption of ce...
CVE-2025-42930MEDIUM6.5SAP Business Planning and Consolidation allows an authenticated standard user to call a function module by crafting spec...
CVE-2025-42929HIGH8.1Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbi...
CVE-2025-42927LOW3.4SAP NetWeaver AS Java application uses Adobe Document Service, installed with a vulnerable version of OpenSSL.Successful...
CVE-2025-42926MEDIUM5.3SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access inter...
CVE-2025-42925MEDIUM4.3Due to the lack of randomness in assigning Object Identifiers in the SAP NetWeaver AS JAVA IIOP service, an authenticate...
CVE-2025-42923MEDIUM4.3Due to insufficient CSRF protection in SAP Fiori App Manage Work Center Groups, an authenticated user could be tricked b...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now