2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-49746HIGH8.8Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.
CVE-2025-47995HIGH8.8Weak authentication in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.
CVE-2025-47158CRITICAL9Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges ov...
CVE-2025-45157MEDIUM6.5Insecure permissions in Splashin iOS v2.0 allow unauthorized attackers to access location data for specific users.
CVE-2025-45156MEDIUM5.3Splashin iOS v2.0 fails to enforce server-side interval restrictions for location updates for free-tier users.
CVE-2025-7791MEDIUM5.4A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0. It has been declared as problematic. T...
CVE-2025-7790MEDIUM6.5A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been classified as critical. This affects an unknown part...
CVE-2025-7789LOW3.7A vulnerability was found in Xuxueli xxl-job up to 3.1.1 and classified as problematic. Affected by this issue is the fu...
CVE-2025-54079HIGH8.8WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection...
CVE-2025-54078MEDIUM6.1WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro...
CVE-2025-54077MEDIUM6.1WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro...
CVE-2025-54076MEDIUM6.1WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro...
CVE-2025-54075HIGH8.3MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to version 0.1...
CVE-2025-54073HIGH7.5mcp-package-docs is an MCP (Model Context Protocol) server that provides LLMs with efficient access to package documenta...
CVE-2025-54059MEDIUM4.4melange allows users to build apk packages using declarative pipelines. Starting in version 0.23.0 and prior to version ...
CVE-2025-53945HIGH7apko allows users to build and publish OCI container images built from apk packages. Starting in version 0.27.0 and prio...
CVE-2025-53888CRITICAL9.8RIOT-OS, an operating system that supports Internet of Things devices, has an ineffective size check implemented with `a...
CVE-2025-7788HIGH8.8A vulnerability has been found in Xuxueli xxl-job up to 3.1.1 and classified as critical. Affected by this vulnerability...
CVE-2025-7787HIGH8.8A vulnerability, which was classified as critical, was found in Xuxueli xxl-job up to 3.1.1. Affected is the function ht...
CVE-2025-46732MEDIUM5.4OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6....
CVE-2025-46000MEDIUM6.5An arbitrary file upload vulnerability in the component /rsc/filemanager.rsc.class.php of Filemanager commit c75b914 v.2...
CVE-2025-7786MEDIUM5.4A vulnerability, which was classified as problematic, has been found in Gnuboard g6 up to 6.0.10. This issue affects som...
CVE-2025-7784MEDIUM6.5A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are e...
CVE-2025-46002MEDIUM6.5An issue in Filemanager v2.5.0 and below allows attackers to execute a directory traversal via sending a crafted HTTP re...
CVE-2025-46001CRITICAL9.8An arbitrary file upload vulnerability in the is_allowed_file_type() function of Filemanager v2.3.0 allows attackers to ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now