2025 CVE Vulnerabilities

45,259 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-49535CRITICAL9.3ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity ...
CVE-2025-43584MEDIUM5.5Substance3D - Viewer versions 0.22 and earlier are affected by an out-of-bounds read vulnerability that could lead to di...
CVE-2025-43583MEDIUM5.5Substance3D - Viewer versions 0.22 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead ...
CVE-2025-43582HIGH7.8Substance3D - Viewer versions 0.22 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could res...
CVE-2025-7193CRITICAL9.8A vulnerability was found in itsourcecode Agri-Trading Online Shopping System up to 1.0. It has been classified as criti...
CVE-2025-7192HIGH8.8A vulnerability was found in D-Link DIR-645 up to 1.05B01 and classified as critical. This issue affects the function ss...
CVE-2025-53355HIGH7.5MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. A command injection vulne...
CVE-2025-37103CRITICAL9.8Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of i...
CVE-2025-7191CRITICAL9.8A vulnerability has been found in code-projects Student Enrollment System 1.0 and classified as critical. This vulnerabi...
CVE-2025-7190HIGH8.8A vulnerability, which was classified as critical, was found in code-projects Library Management System 2.0. This affect...
CVE-2025-48386MEDIUM6.3Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-...
CVE-2025-48385HIGH8.6Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-...
CVE-2025-48384HIGH8Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-...
CVE-2025-37102HIGH7.2An authenticated command injection vulnerability exists in the Command line interface of HPE Networking Instant On Acces...
CVE-2025-27369MEDIUM4.3IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to information disclosure of sensitive information due to a ...
CVE-2025-27367MEDIUM6.5IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to improper input validation due to bypassing of client-side v...
CVE-2025-7363MEDIUM5.4The TitleIcon extension for MediaWiki is vulnerable to stored XSS through the #titleicon_unicode parser function. User i...
CVE-2025-7362MEDIUM5.4The MsUpload extension for MediaWiki is vulnerable to stored XSS via the msu-continue system message, which is inserted ...
CVE-2025-7189HIGH8.8A vulnerability, which was classified as critical, has been found in code-projects Chat System 1.0. Affected by this iss...
CVE-2025-7188HIGH8.8A vulnerability classified as critical was found in code-projects Chat System 1.0. Affected by this vulnerability is an ...
CVE-2025-53479MEDIUM5.4The CheckUser extension’s Special:CheckUser interface is vulnerable to reflected XSS via the rev-deleted-user message. T...
CVE-2025-4663MEDIUM4.9An Improper Check for Unusual or Exceptional Conditions vulnerability in Brocade Fabric OS before 9.2.2.a could allow ...
CVE-2025-47135MEDIUM5.5Dimension versions 4.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure o...
CVE-2025-30312HIGH7.8Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary...
CVE-2025-0928HIGH8.8In Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent bina...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now