2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-6971HIGH7.8Use After Free vulnerability exists in the CATPRODUCT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWOR...
CVE-2025-53622MEDIUM5.2DSpace open source software is a repository application which provides durable access to digital resources. Prior to ver...
CVE-2025-53621MEDIUM6.9DSpace open source software is a repository application which provides durable access to digital resources. Two related ...
CVE-2025-52379MEDIUM5.4Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below contains an authenticated command injection vulnerabili...
CVE-2025-52378MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below allowing at...
CVE-2025-52377MEDIUM5.4Command injection vulnerability in Nexxt Solutions NCM-X1800 Mesh Router versions UV1.2.7 and below, allowing authentica...
CVE-2025-48795MEDIUM5.6Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which mea...
CVE-2025-33097MEDIUM5.4IBM QRadar SIEM 7.5 - 7.5.0 UP12 IF02 is vulnerable to stored cross-site scripting. This vulnerability allows authentica...
CVE-2025-30483MEDIUM5.5Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0 contains an Insertion of Sensitive Information into Log ...
CVE-2025-0831HIGH7.8Out-Of-Bounds Read vulnerability exists in the JT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS D...
CVE-2025-6965HIGH7.7There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the numbe...
CVE-2025-52376CRITICAL9.8An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router ...
CVE-2025-34116HIGH8.7A remote command execution vulnerability exists in IPFire before version 2.19 Core Update 101 via the 'proxy.cgi' CGI in...
CVE-2025-34115HIGH8.7An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter...
CVE-2025-34113HIGH8.7An authenticated command injection vulnerability exists in Tiki Wiki CMS versions ≤14.1, ≤12.4 LTS, ≤9.10 LTS, and ≤6.14...
CVE-2025-34112CRITICAL10An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpr...
CVE-2025-34111CRITICAL9.8An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via th...
CVE-2025-34110CRITICAL9.3A directory traversal vulnerability exists in ColoradoFTP Server ≤ 1.3 Build 8 for Windows, allowing unauthenticated att...
CVE-2025-34109HIGH8.5PSEvents.exe in multiple Panda Security products runs hourly with SYSTEM privileges and loads DLL files from a user-writ...
CVE-2025-34108HIGH8.6A stack-based buffer overflow vulnerability exists in the login functionality of Disk Pulse Enterprise version 9.0.34. A...
CVE-2025-34107HIGH8.7A buffer overflow vulnerability exists in the WinaXe FTP Client version 7.7 within the FTP banner parsing functionality,...
CVE-2025-34106HIGH8.4A buffer overflow vulnerability exists in PDF Shaper versions 3.5 and 3.6 when converting a crafted PDF file to an image...
CVE-2025-34105CRITICAL10A stack-based buffer overflow vulnerability exists in the built-in web interface of DiskBoss Enterprise versions 7.4.28,...
CVE-2025-34104CRITICAL9.4An authenticated remote code execution vulnerability exists in Piwik (now Matomo) versions prior to 3.0.3 via the plugin...
CVE-2025-34103CRITICAL9.3An unauthenticated command injection vulnerability exists in WePresent WiPG-1000 firmware versions prior to 2.2.3.0, due...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now