2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-8462MEDIUM6.4The RT Easy Builder – Advanced addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2025-5391HIGH8.1The WooCommerce Purchase Orders plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p...
CVE-2025-4390MEDIUM5.3The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, ...
CVE-2025-42976HIGH8.1SAP NetWeaver Application Server ABAP (BIC Document) allows an authenticated attacker to craft a request that, when subm...
CVE-2025-42975MEDIUM6.1SAP NetWeaver Application Server ABAP (BIC Document) allows an unauthenticated attacker to craft a URL link which, when ...
CVE-2025-42957CRITICAL9.9SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. T...
CVE-2025-42955LOW3.5Due to a missing authorization check in SAP Cloud Connector, an attacker on an adjacent network with low privileges coul...
CVE-2025-42951HIGH8.8Due to broken authorization, SAP Business One (SLD) allows an authenticated attacker to gain administrator privileges of...
CVE-2025-42950CRITICAL9.9SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function mo...
CVE-2025-42949MEDIUM4.9Due to a missing authorization check in the ABAP Platform, an authenticated user with elevated privileges could bypass a...
CVE-2025-42948MEDIUM6.1Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform, an unauthenticated attacker could gene...
CVE-2025-42946MEDIUM6.9Due to directory traversal vulnerability in SAP S/4HANA (Bank Communication Management), an attacker with high privilege...
CVE-2025-42945MEDIUM6.1SAP NetWeaver Application Server ABAP has HTML injection vulnerability. Due to this, an attacker could craft a URL with ...
CVE-2025-42943MEDIUM4.5SAP GUI for Windows may allow the leak of NTML hashes when specific ABAP frontend services are called with UNC paths. Fo...
CVE-2025-42942MEDIUM6.1SAP NetWeaver Application Server for ABAP has cross-site scripting vulnerability. Due to this, an unauthenticated attack...
CVE-2025-42941LOW3.5SAP Fiori (Launchpad) is vulnerable to Reverse Tabnabbing vulnerability due to inadequate external navigation protection...
CVE-2025-42936MEDIUM5.4The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations fo...
CVE-2025-42935MEDIUM4.1The SAP NetWeaver Application Server ABAP and ABAP Platform Internet Communication Manager (ICM) permits authorized user...
CVE-2025-42934MEDIUM4.3SAP S/4HANA Supplier invoice is vulnerable to CRLF Injection. An attacker with user-level privileges can bypass the allo...
CVE-2025-55161CRITICAL9.8Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, ...
CVE-2025-55159MEDIUM5.1slab is a pre-allocated storage for a uniform data type. In version 0.4.10, the get_disjoint_mut method incorrectly chec...
CVE-2025-55158HIGH8.8Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1406, when processing nested tu...
CVE-2025-55157HIGH8.8Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1400, When processing nested tu...
CVE-2025-55156HIGH7.8pyLoad is the free and open-source Download Manager written in pure Python. Prior to version 0.5.0b3.dev91, the paramete...
CVE-2025-55151CRITICAL9.8Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now