2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-6390MEDIUM4.4Brocade SANnav before SANnav 2.4.0a logs passwords and pbe keys in the Brocade SANnav server audit logs after installati...
CVE-2025-4662MEDIUM4.4Brocade SANnav before SANnav 2.4.0a logs plaintext passphrases in the Brocade SANnav host server audit logs while execut...
CVE-2025-3947HIGH8.2The Honeywell Experion PKS contains an Integer Underflow vulnerability in the component Control Data Access (CDA). A...
CVE-2025-3946HIGH8.2The Honeywell Experion PKS and OneWireless WDM contains a Deployment of Wrong Handler vulnerability in the comp...
CVE-2025-2523CRITICAL9.4The Honeywell Experion PKS and OneWireless WDM contains an Integer Underflow vulnerability in the component Con...
CVE-2025-2522MEDIUM6.5The Honeywell Experion PKS and OneWireless WDM contains Sensitive Information in Resource vulnerability in the compon...
CVE-2025-2521HIGH8.6The Honeywell Experion PKS and OneWireless WDM contains a Memory Buffer vulnerability in the component Control Data Acce...
CVE-2025-7413HIGH8.8A vulnerability classified as critical has been found in code-projects Library System 1.0. This affects an unknown part ...
CVE-2025-7412HIGH8.8A vulnerability was found in code-projects Library System 1.0. It has been rated as critical. Affected by this issue is ...
CVE-2025-7021MEDIUM6.5Fullscreen API Spoofing and UI Redressing in the handling of Fullscreen API and UI rendering in OpenAI Operator SaaS on ...
CVE-2025-53634HIGH7.5Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. The HTTP Gateway processes h...
CVE-2025-53633CRITICAL9.8Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. When decoding a scenario (i....
CVE-2025-53632CRITICAL9.1Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. When decoding a scenario (i....
CVE-2025-53630HIGH8.9llama.cpp is an inference of several LLM models in C/C++. Integer Overflow in the gguf_init_from_file_impl function in g...
CVE-2025-53629HIGH7.5cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.23.0, incoming requests usi...
CVE-2025-53628HIGH8.8cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.20.1, cpp-httplib does not ...
CVE-2025-53506HIGH7.5Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial set...
CVE-2025-45662MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component /master/login.php of mpgram-web commit 94baadb allows attack...
CVE-2025-34102CRITICAL9.3A remote code execution vulnerability exists in CryptoLog (PHP version, discontinued since 2009) due to a chained exploi...
CVE-2025-34101CRITICAL9.3An unauthenticated command injection vulnerability exists in Serviio Media Server versions 1.4 through 1.8 on Windows, i...
CVE-2025-34100CRITICAL9.3An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the elFinder 2.0 file man...
CVE-2025-34099CRITICAL9.3An unauthenticated command injection vulnerability exists in VICIdial versions 2.9 RC1 through 2.13 RC1, within the vici...
CVE-2025-34098HIGH7.1A path traversal vulnerability exists in Riverbed SteelHead VCX appliances (confirmed in VCX255U 9.6.0a) due to improper...
CVE-2025-34097HIGH8.6An unrestricted file upload vulnerability exists in ProcessMaker versions prior to 3.5.4 due to improper handling of upl...
CVE-2025-34096CRITICAL9.3A stack-based buffer overflow vulnerability exists in Easy File Sharing HTTP Server version 7.2. The flaw is triggered w...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now