2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8462 | MEDIUM | 6.4 | 0.2% | Aug 12, 2025 | The RT Easy Builder – Advanced addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi... |
| CVE-2025-5391 | HIGH | 8.1 | 0.8% | Aug 12, 2025 | The WooCommerce Purchase Orders plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p... |
| CVE-2025-4390 | MEDIUM | 5.3 | 0.3% | Aug 12, 2025 | The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, ... |
| CVE-2025-42976 | HIGH | 8.1 | 0.4% | Aug 12, 2025 | SAP NetWeaver Application Server ABAP (BIC Document) allows an authenticated attacker to craft a request that, when subm... |
| CVE-2025-42975 | MEDIUM | 6.1 | 0.2% | Aug 12, 2025 | SAP NetWeaver Application Server ABAP (BIC Document) allows an unauthenticated attacker to craft a URL link which, when ... |
| CVE-2025-42957 | CRITICAL | 9.9 | 1.5% | Aug 12, 2025 | SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. T... |
| CVE-2025-42955 | LOW | 3.5 | 0.4% | Aug 12, 2025 | Due to a missing authorization check in SAP Cloud Connector, an attacker on an adjacent network with low privileges coul... |
| CVE-2025-42951 | HIGH | 8.8 | 0.4% | Aug 12, 2025 | Due to broken authorization, SAP Business One (SLD) allows an authenticated attacker to gain administrator privileges of... |
| CVE-2025-42950 | CRITICAL | 9.9 | 0.6% | Aug 12, 2025 | SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function mo... |
| CVE-2025-42949 | MEDIUM | 4.9 | 0.3% | Aug 12, 2025 | Due to a missing authorization check in the ABAP Platform, an authenticated user with elevated privileges could bypass a... |
| CVE-2025-42948 | MEDIUM | 6.1 | 0.2% | Aug 12, 2025 | Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform, an unauthenticated attacker could gene... |
| CVE-2025-42946 | MEDIUM | 6.9 | 0.9% | Aug 12, 2025 | Due to directory traversal vulnerability in SAP S/4HANA (Bank Communication Management), an attacker with high privilege... |
| CVE-2025-42945 | MEDIUM | 6.1 | 0.2% | Aug 12, 2025 | SAP NetWeaver Application Server ABAP has HTML injection vulnerability. Due to this, an attacker could craft a URL with ... |
| CVE-2025-42943 | MEDIUM | 4.5 | 0.3% | Aug 12, 2025 | SAP GUI for Windows may allow the leak of NTML hashes when specific ABAP frontend services are called with UNC paths. Fo... |
| CVE-2025-42942 | MEDIUM | 6.1 | 0.2% | Aug 12, 2025 | SAP NetWeaver Application Server for ABAP has cross-site scripting vulnerability. Due to this, an unauthenticated attack... |
| CVE-2025-42941 | LOW | 3.5 | 0.2% | Aug 12, 2025 | SAP Fiori (Launchpad) is vulnerable to Reverse Tabnabbing vulnerability due to inadequate external navigation protection... |
| CVE-2025-42936 | MEDIUM | 5.4 | 0.2% | Aug 12, 2025 | The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations fo... |
| CVE-2025-42935 | MEDIUM | 4.1 | 0.1% | Aug 12, 2025 | The SAP NetWeaver Application Server ABAP and ABAP Platform Internet Communication Manager (ICM) permits authorized user... |
| CVE-2025-42934 | MEDIUM | 4.3 | 0.2% | Aug 12, 2025 | SAP S/4HANA Supplier invoice is vulnerable to CRLF Injection. An attacker with user-level privileges can bypass the allo... |
| CVE-2025-55161 | CRITICAL | 9.8 | 1.9% | Aug 11, 2025 | Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, ... |
| CVE-2025-55159 | MEDIUM | 5.1 | 0.2% | Aug 11, 2025 | slab is a pre-allocated storage for a uniform data type. In version 0.4.10, the get_disjoint_mut method incorrectly chec... |
| CVE-2025-55158 | HIGH | 8.8 | 0.3% | Aug 11, 2025 | Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1406, when processing nested tu... |
| CVE-2025-55157 | HIGH | 8.8 | 0.3% | Aug 11, 2025 | Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1400, When processing nested tu... |
| CVE-2025-55156 | HIGH | 7.8 | 0.3% | Aug 11, 2025 | pyLoad is the free and open-source Download Manager written in pure Python. Prior to version 0.5.0b3.dev91, the paramete... |
| CVE-2025-55151 | CRITICAL | 9.8 | 0.3% | Aug 11, 2025 | Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now