2025 CVE Vulnerabilities
45,251 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-42922 | CRITICAL | 9.9 | 0.7% | Sep 9, 2025 | SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw in an available servic... |
| CVE-2025-42920 | MEDIUM | 6.1 | 0.2% | Sep 9, 2025 | Due to a Cross-Site Scripting (XSS) vulnerability in the SAP Supplier Relationship Management, an unauthenticated attack... |
| CVE-2025-42918 | MEDIUM | 4.3 | 0.2% | Sep 9, 2025 | SAP NetWeaver Application Server for ABAP allows authenticated users with access to background processing to gain unauth... |
| CVE-2025-42917 | MEDIUM | 6.5 | 0.2% | Sep 9, 2025 | SAP HCM Approve Timesheets Fiori 2.0 application does not perform necessary authorization checks for an authenticated us... |
| CVE-2025-42916 | HIGH | 8.1 | 0.2% | Sep 9, 2025 | Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbi... |
| CVE-2025-42915 | MEDIUM | 5.4 | 0.2% | Sep 9, 2025 | Fiori app Manage Payment Blocks does not perform the necessary authorization checks, allowing an attacker with basic use... |
| CVE-2025-42914 | LOW | 3.1 | 0.2% | Sep 9, 2025 | Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in... |
| CVE-2025-42913 | LOW | 3.1 | 0.2% | Sep 9, 2025 | Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in... |
| CVE-2025-42912 | MEDIUM | 6.5 | 0.2% | Sep 9, 2025 | SAP HCM My Timesheet Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, re... |
| CVE-2025-42911 | MEDIUM | 4.3 | 0.2% | Sep 9, 2025 | SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled function module, which could... |
| CVE-2025-10121 | MEDIUM | 6.3 | 0.2% | Sep 9, 2025 | A flaw has been found in uverif up to 3.2. This affects the function addbatch of the file /admin/kami_list. This manipul... |
| CVE-2025-10120 | HIGH | 8.8 | 0.8% | Sep 9, 2025 | A vulnerability was detected in Tenda AC20 up to 16.03.08.12. The impacted element is the function strcpy of the file /g... |
| CVE-2025-10118 | CRITICAL | 9.8 | 0.5% | Sep 9, 2025 | A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. The... |
| CVE-2025-10117 | MEDIUM | 5.4 | 0.3% | Sep 9, 2025 | A weakness has been identified in SourceCodester Simple To-Do List System 1.0. Impacted is an unknown function of the fi... |
| CVE-2025-10116 | HIGH | 7.3 | 0.4% | Sep 9, 2025 | A vulnerability was identified in SiempreCMS up to 1.3.6. This vulnerability affects unknown code of the file /docs/admi... |
| CVE-2025-43774 | — | — | — | Sep 9, 2025 | Rejected reason: This CVE ID is rejected. The reported vulnerability was found to be present only in a feature that was ... |
| CVE-2025-10115 | HIGH | 7.3 | 0.3% | Sep 9, 2025 | A vulnerability was determined in SiempreCMS up to 1.3.6. This affects an unknown part of the file user_search_ajax.php.... |
| CVE-2025-10114 | CRITICAL | 9.8 | 0.4% | Sep 9, 2025 | A vulnerability was found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file ... |
| CVE-2025-58757 | HIGH | 8.8 | 0.6% | Sep 9, 2025 | MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, the... |
| CVE-2025-58756 | HIGH | 8.8 | 0.7% | Sep 9, 2025 | MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, in ... |
| CVE-2025-58755 | HIGH | 8.8 | 0.6% | Sep 9, 2025 | MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. The extractall function `zip_file.extracta... |
| CVE-2025-43763 | MEDIUM | 6.5 | 0.2% | Sep 9, 2025 | A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP... |
| CVE-2025-10113 | CRITICAL | 9.8 | 0.4% | Sep 9, 2025 | A security vulnerability has been detected in itsourcecode Student Information Management System 1.0. This affects an un... |
| CVE-2025-10112 | CRITICAL | 9.8 | 0.4% | Sep 9, 2025 | A weakness has been identified in itsourcecode Student Information Management System 1.0. The impacted element is an unk... |
| CVE-2025-58752 | MEDIUM | 5.3 | 0.6% | Sep 8, 2025 | Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files o... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now