2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-34095CRITICAL9.3An OS command injection vulnerability exists in Mako Server versions 2.5 and 2.6, specifically within the tutorial inter...
CVE-2025-34093HIGH7.5An authenticated command injection vulnerability exists in the Polycom HDX Series command shell interface accessible ove...
CVE-2025-2520HIGH7.5The Honeywell Experion PKS contains an Uninitialized Variable in the common Epic Platform Analyzer (EPA) communications....
CVE-2025-7411CRITICAL9.8A vulnerability was found in code-projects LifeStyle Store 1.0. It has been declared as critical. Affected by this vulne...
CVE-2025-53709MEDIUM5.4Secure-upload is a data submission service that validates single-use tokens when accepting submissions to channels. The ...
CVE-2025-53626MEDIUM6.1pdfme is a TypeScript-based PDF generator and React-based UI. The expression evaluation feature in pdfme 5.2.0 to 5.4.0 ...
CVE-2025-53625HIGH8.7The DynamicPageList3 extension is a reporting tool for MediaWiki, listing category members and intersections with variou...
CVE-2025-53549MEDIUM5.2The Matrix Rust SDK is a collection of libraries that make it easier to build Matrix clients in Rust. An SQL injection v...
CVE-2025-53542HIGH7.7Headlamp is an extensible Kubernetes web UI. A command injection vulnerability was discovered in the codeSign.js script ...
CVE-2025-53503HIGH7.8Trend Micro Cleaner One Pro is vulnerable to a Privilege Escalation vulnerability that could allow a local attacker to u...
CVE-2025-53378CRITICAL9.8A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have all...
CVE-2025-52837HIGH7.8Trend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link Following Privilege Escalat...
CVE-2025-52521HIGH7.1Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that cou...
CVE-2025-52520HIGH7.5For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a...
CVE-2025-52473MEDIUM5.5liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Mult...
CVE-2025-52434HIGH7.5Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomc...
CVE-2025-28245MEDIUM6.1Cross-site scripting (XSS) vulnerability in Alteryx Server 2023.1.1.460 allows remote attackers to inject arbitrary web ...
CVE-2025-28244HIGH8.8Insecure Permissions vulnerability in the Local Storage in Alteryx Server 2023.1.1.460 allows remote attackers to obtain...
CVE-2025-28243HIGH8An issue in Alteryx Server v.2023.1.1.460 allows HTML injection via a crafted script to the pages component.
CVE-2025-53371CRITICAL9.1DiscordNotifications is an extension for MediaWiki that sends notifications of actions in your Wiki to a Discord channel...
CVE-2025-7410CRITICAL9.8A vulnerability was found in code-projects LifeStyle Store 1.0. It has been classified as critical. Affected is an unkno...
CVE-2025-7409CRITICAL9.8A vulnerability was found in code-projects Mobile Shop 1.0 and classified as critical. This issue affects some unknown p...
CVE-2025-53020HIGH7.5Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Ser...
CVE-2025-49812HIGH7.4In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows...
CVE-2025-49630HIGH7.5In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now