2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-65176HIGH7.5An issue was discovered in Dynatrace OneAgent before 1.325.47. When attempting to access a remote network share from a m...
CVE-2025-66440HIGH8.8An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext/acc...
CVE-2025-66439HIGH8.8An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext.acc...
CVE-2025-66438HIGH8.8A Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNext through 15.89.0 Print Format renderin...
CVE-2025-66437HIGH8.8An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext throug...
CVE-2025-14038HIGH7EDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints. Th...
CVE-2025-66434HIGH8.8An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning_letter_text method of Frappe ERPNext th...
CVE-2025-65742HIGH8.2An unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11.0 allows attackers to...
CVE-2025-11393HIGH8.7A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of...
CVE-2025-60786HIGH8.8A Zip Slip vulnerability in the import a Project component of iceScrum v7.54 Pro On-prem allows attackers to execute arb...
CVE-2025-13824HIGH8.7A security issue exists due to improper handling of malformed CIP packets during fuzzing. The controller enters a hard f...
CVE-2025-13823HIGH7.1A security issue was found in the IPv6 stack in the Micro850 and Micro870 controllers when the controllers received mult...
CVE-2025-34181HIGH8.7NetSupport Manager < 14.12.0001 contains an arbitrary file write vulnerability in its Connectivity Server/Gateway PUTFIL...
CVE-2025-34180HIGH8.4NetSupport Manager < 14.12.0001 relies on a shared Gateway Key for authentication between Manager/Control, Client, and ...
CVE-2025-34179HIGH8.7NetSupport Manager < 14.12.0001 contains an unauthenticated SQL injection vulnerability in its Connectivity Server/Gatew...
CVE-2025-14383HIGH7.5The Booking Calendar plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'dates_to_check' param...
CVE-2025-65781HIGH8.2An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upl...
CVE-2025-65780HIGH8.8An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authenticated ...
CVE-2025-65779HIGH7.5An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Unauthenticate...
CVE-2025-65778HIGH8.1An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Uploaded attac...
CVE-2025-37731HIGH7.4Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica...
CVE-2025-14708HIGH7.5A weakness has been identified in Shiguangwu sgwbox N3 2.0.25. Affected by this vulnerability is an unknown functionalit...
CVE-2025-14712HIGH8.7Student Learning Assessment and Support System developed by JHENG GAO has a Exposure of Sensitive Information vulnerabil...
CVE-2025-14549HIGH8.1In the Eclipse OMR compiler component, since release 0.7.0, an optimization enabled for Eclipse OpenJ9 consumers of OMR ...
CVE-2025-13355HIGH7.1The URL Shortify WordPress plugin before 1.11.4 does not sanitise and escape a parameter before outputting it back in t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now