2025 CVE Vulnerabilities

45,251 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-42922CRITICAL9.9SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw in an available servic...
CVE-2025-42920MEDIUM6.1Due to a Cross-Site Scripting (XSS) vulnerability in the SAP Supplier Relationship Management, an unauthenticated attack...
CVE-2025-42918MEDIUM4.3SAP NetWeaver Application Server for ABAP allows authenticated users with access to background processing to gain unauth...
CVE-2025-42917MEDIUM6.5SAP HCM Approve Timesheets Fiori 2.0 application does not perform necessary authorization checks for an authenticated us...
CVE-2025-42916HIGH8.1Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbi...
CVE-2025-42915MEDIUM5.4Fiori app Manage Payment Blocks does not perform the necessary authorization checks, allowing an attacker with basic use...
CVE-2025-42914LOW3.1Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in...
CVE-2025-42913LOW3.1Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in...
CVE-2025-42912MEDIUM6.5SAP HCM My Timesheet Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, re...
CVE-2025-42911MEDIUM4.3SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled function module, which could...
CVE-2025-10121MEDIUM6.3A flaw has been found in uverif up to 3.2. This affects the function addbatch of the file /admin/kami_list. This manipul...
CVE-2025-10120HIGH8.8A vulnerability was detected in Tenda AC20 up to 16.03.08.12. The impacted element is the function strcpy of the file /g...
CVE-2025-10118CRITICAL9.8A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. The...
CVE-2025-10117MEDIUM5.4A weakness has been identified in SourceCodester Simple To-Do List System 1.0. Impacted is an unknown function of the fi...
CVE-2025-10116HIGH7.3A vulnerability was identified in SiempreCMS up to 1.3.6. This vulnerability affects unknown code of the file /docs/admi...
CVE-2025-43774Rejected reason: This CVE ID is rejected. The reported vulnerability was found to be present only in a feature that was ...
CVE-2025-10115HIGH7.3A vulnerability was determined in SiempreCMS up to 1.3.6. This affects an unknown part of the file user_search_ajax.php....
CVE-2025-10114CRITICAL9.8A vulnerability was found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file ...
CVE-2025-58757HIGH8.8MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, the...
CVE-2025-58756HIGH8.8MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, in ...
CVE-2025-58755HIGH8.8MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. The extractall function `zip_file.extracta...
CVE-2025-43763MEDIUM6.5A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP...
CVE-2025-10113CRITICAL9.8A security vulnerability has been detected in itsourcecode Student Information Management System 1.0. This affects an un...
CVE-2025-10112CRITICAL9.8A weakness has been identified in itsourcecode Student Information Management System 1.0. The impacted element is an unk...
CVE-2025-58752MEDIUM5.3Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files o...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now