2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-31513MEDIUM6.5An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can elevate to administrator privileges via the Is...
CVE-2025-31512HIGH7.3An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can bypass manager approval via isAddedByApprover ...
CVE-2025-31511HIGH7.3An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can bypass manager approval by changing the user I...
CVE-2025-51479MEDIUM5.4Authorization bypass in update_user_group in onyx-dot-app Onyx Enterprise Edition 0.27.0 allows remote authenticated att...
CVE-2025-51471MEDIUM6.9Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authen...
CVE-2025-51459MEDIUM6.5File Upload vulnerability in agent.hub.controller.refresh_plugins in eosphoros-ai DB-GPT 0.7.0 allows remote attackers t...
CVE-2025-51464HIGH8.8Cross-site Scripting (XSS) in aimhubio Aim 3.28.0 allows remote attackers to execute arbitrary JavaScript in victims bro...
CVE-2025-48964MEDIUM6.5ping in iputils before 20250602 allows a denial of service (application error in adaptive ping mode or incorrect data co...
CVE-2025-6741HIGH7.7Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthor...
CVE-2025-6523CRITICAL9.5Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker t...
CVE-2025-51482HIGH8.8Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows rem...
CVE-2025-51481MEDIUM6.6Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC...
CVE-2025-8019HIGH8.8A vulnerability was found in Shenzhen Libituo Technology LBT-T300-T310 2.2.3.6. It has been rated as critical. Affected ...
CVE-2025-7371MEDIUM6.8Okta On-Premises Provisioning (OPP) agents log certain user data during administrator-initiated password resets. This vu...
CVE-2025-5042HIGH7.8A maliciously crafted RFA file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A mal...
CVE-2025-51480HIGH8.8Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrit...
CVE-2025-51463HIGH7Path Traversal in restore_run_backup() in AIM 3.28.0 allows remote attackers to write arbitrary files to the server's fi...
CVE-2025-48498HIGH7.5A null pointer dereference vulnerability exists in the Distributed Transaction component of Bloomberg Comdb2 8.1 when pr...
CVE-2025-46354HIGH7.5A denial of service vulnerability exists in the Distributed Transaction Commit/Abort Operation functionality of Bloomber...
CVE-2025-36520HIGH7.5A null pointer dereference vulnerability exists in the net_connectmsg Protocol Buffer Message functionality of Bloomberg...
CVE-2025-36512HIGH7.5A denial of service vulnerability exists in the Bloomberg Comdb2 8.1 database when handling a distributed transaction he...
CVE-2025-35966HIGH7.5A null pointer dereference vulnerability exists in the CDB2SQLQUERY protocol buffer message handling of Bloomberg Comdb2...
CVE-2025-8018HIGH8.8A vulnerability was found in code-projects Food Ordering Review System 1.0. It has been declared as critical. Affected b...
CVE-2025-8015MEDIUM6.4The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an ...
CVE-2025-51865HIGH8.8Ai2 playground web service (playground.allenai.org) LLM chat through 2025-06-03 is vulnerable to Insecure Direct Object ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now