2025 CVE Vulnerabilities

45,262 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-6797HIGH7.5Marvell QConvergeConsole getFileUploadBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability...
CVE-2025-6796HIGH7.5Marvell QConvergeConsole getAppFileBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability al...
CVE-2025-6795HIGH7.5Marvell QConvergeConsole getFileUploadSize Directory Traversal Information Disclosure Vulnerability. This vulnerability ...
CVE-2025-6794CRITICAL9.8Marvell QConvergeConsole saveAsText Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows r...
CVE-2025-6793CRITICAL9.4Marvell QConvergeConsole QLogicDownloadImpl Directory Traversal Arbitrary File Deletion and Information Disclosure Vulne...
CVE-2025-6714HIGH7.5MongoDB Server's mongos component can become unresponsive to new connections due to incorrect handling of incomplete dat...
CVE-2025-6713MEDIUM6.5An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization d...
CVE-2025-6712MEDIUM6.5MongoDB Server may be susceptible to disruption caused by high memory usage, potentially leading to server crash. This c...
CVE-2025-6711MEDIUM4.9An issue has been identified in MongoDB Server where unredacted queries may inadvertently appear in server logs when cer...
CVE-2025-6663HIGH7.8GStreamer H266 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows ...
CVE-2025-5987HIGH8.1A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust th...
CVE-2025-53486MEDIUM5.4The WikiCategoryTagCloud extension is vulnerable to reflected XSS via the linkstyle attribute, which is improperly conca...
CVE-2025-43930CRITICAL9.8Hashview 0.8.1 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a r...
CVE-2025-7131CRITICAL9.8A vulnerability was found in Campcodes Payroll Management System 1.0. It has been declared as critical. Affected by this...
CVE-2025-7130CRITICAL9.8A vulnerability was found in Campcodes Payroll Management System 1.0. It has been classified as critical. Affected is an...
CVE-2025-7056MEDIUM6.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2025-7129CRITICAL9.8A vulnerability was found in Campcodes Payroll Management System 1.0 and classified as critical. This issue affects some...
CVE-2025-7128CRITICAL9.8A vulnerability has been found in Campcodes Payroll Management System 1.0 and classified as critical. This vulnerability...
CVE-2025-6209HIGH7.5A path traversal vulnerability exists in run-llama/llama_index versions 0.12.27 through 0.12.40, specifically within the...
CVE-2025-7127HIGH7.2A vulnerability, which was classified as critical, was found in itsourcecode Employee Management System up to 1.0. This ...
CVE-2025-7126HIGH7.2A vulnerability, which was classified as critical, has been found in itsourcecode Employee Management System up to 1.0. ...
CVE-2025-7125HIGH7.2A vulnerability classified as critical was found in itsourcecode Employee Management System up to 1.0. Affected by this ...
CVE-2025-7124HIGH8.8A vulnerability classified as critical has been found in code-projects Online Note Sharing 1.0. Affected is an unknown f...
CVE-2025-7123HIGH7.2A vulnerability was found in Campcodes Complaint Management System 1.0. It has been rated as critical. This issue affect...
CVE-2025-7122CRITICAL9.8A vulnerability was found in Campcodes Complaint Management System 1.0. It has been declared as critical. This vulnerabi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now