2025 CVE Vulnerabilities

45,264 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-53359MEDIUM6.9ethereum is a common ethereum structs for Rust. Prior to ethereum crate v0.18.0, signature malleability (according to EI...
CVE-2025-53358MEDIUM6.5kotaemon is an open-source RAG-based tool for document comprehension. From versions 0.10.6 and prior, in libs/ktem/ktem/...
CVE-2025-52886MEDIUM5.9Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std...
CVE-2025-20310MEDIUM6.1A vulnerability in the web UI of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker t...
CVE-2025-20308MEDIUM6.7A vulnerability in Cisco Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute...
CVE-2025-6725MEDIUM5.4In the PdfViewer component, a Cross-Site Scripting (XSS) vulnerability is possible if a specially-crafted document has a...
CVE-2025-53494MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2025-53493MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2025-53492LOW3.7Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2025-53110HIGH7.3Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versio...
CVE-2025-53109HIGH7.3Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versio...
CVE-2025-53108MEDIUM5.3HomeBox is a home inventory and organization system. Prior to 0.20.1, HomeBox contains a missing authorization check in ...
CVE-2025-53006CRITICAL9.8DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, in both PostgreS...
CVE-2025-52891MEDIUM6.5ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versio...
CVE-2025-38093MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: arm64: dts: qcom: x1e80100: Add GPU cooling Unlike...
CVE-2025-38092MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ksmbd: use list_first_entry_or_null for opinfo_get_...
CVE-2025-38091HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: check stream id dml21 wrapper to g...
CVE-2025-53106HIGH8.8Graylog is a free and open log management platform. In versions 6.2.0 to before 6.2.4 and 6.3.0-alpha.1 to before 6.3.0-...
CVE-2025-49588HIGH8.7Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. In ve...
CVE-2025-45029MEDIUM6.5WINSTAR WN572HP3 v230525 was discovered to contain a heap overflow via the CONTENT_LENGTH variable at /cgi-bin/upload.cg...
CVE-2025-34073CRITICAL10An unauthenticated command injection vulnerability exists in stamparm/maltrail (Maltrail) versions <=0.54. A remote atta...
CVE-2025-34072CRITICAL9.3A data exfiltration vulnerability exists in Anthropic’s deprecated Slack Model Context Protocol (MCP) Server via automat...
CVE-2025-34071CRITICAL9.8A remote code execution vulnerability in GFI Kerio Control 9.4.5 allows attackers with administrative access to upload a...
CVE-2025-34070CRITICAL9.8A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remot...
CVE-2025-34069CRITICAL9.8An authentication bypass vulnerability exists in GFI Kerio Control 9.4.5 due to insecure default proxy configuration and...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now