2025 CVE Vulnerabilities

45,266 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-52480CRITICAL9.8Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General regi...
CVE-2025-4656LOW3.1Vault Community and Vault Enterprise rekey and recovery key operations can lead to a denial of service due to uncontroll...
CVE-2025-49153CRITICAL9.3The affected products could allow an unauthenticated attacker to overwrite files and execute arbitrary code.
CVE-2025-49152HIGH8.7The affected products contain JSON Web Tokens (JWT) that do not expire, which could allow an attacker to gain access to ...
CVE-2025-49151CRITICAL9.3The affected products could allow an unauthenticated attacker to generate forged JSON Web Tokens (JWT) to bypass authent...
CVE-2025-20282CRITICAL10A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upl...
CVE-2025-6615HIGH8.8A vulnerability, which was classified as critical, was found in D-Link DIR-619L 2.06B01. This affects the function formA...
CVE-2025-6614HIGH8.8A vulnerability, which was classified as critical, has been found in D-Link DIR-619L 2.06B01. Affected by this issue is ...
CVE-2025-6612CRITICAL9.8A vulnerability was found in code-projects Inventory Management System 1.0. It has been rated as critical. This issue af...
CVE-2025-6611CRITICAL9.8A vulnerability was found in code-projects Inventory Management System 1.0. It has been declared as critical. This vulne...
CVE-2025-52479HIGH7.7HTTP.jl provides HTTP client and server functionality for Julia, and URIs.jl parses and works with Uniform Resource Iden...
CVE-2025-50179MEDIUM4.3Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker could use a...
CVE-2025-50178MEDIUM6.6GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 0.4.3 lack input validation for ...
CVE-2025-49845HIGH7.5Discourse is an open-source discussion platform. The visibility of posts typed `whisper` is controlled via the `whispers...
CVE-2025-44206MEDIUM4.6Hexagon HxGN OnCall Dispatch Advantage (Web) v10.2309.03.00264 and Hexagon HxGN OnCall Dispatch Advantage (Mobile) v10.2...
CVE-2025-25905HIGH7.1Cross-Site Scripting (XSS) vulnerability in CADClick v1.13.0 and before allows remote attackers to inject arbitrary web ...
CVE-2025-20281CRITICAL10A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to exec...
CVE-2025-20264MEDIUM6.4A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat...
CVE-2025-6610HIGH7.2A vulnerability was found in itsourcecode Employee Management System up to 1.0. It has been classified as critical. This...
CVE-2025-6609HIGH8.8A vulnerability was found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected by thi...
CVE-2025-6608HIGH8.8A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected b...
CVE-2025-49135MEDIUM6.5CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.2.0 through 2.39.0 ha...
CVE-2025-6607HIGH8.8A vulnerability, which was classified as critical, was found in SourceCodester Best Salon Management System 1.0. Affecte...
CVE-2025-6606HIGH8.8A vulnerability, which was classified as critical, has been found in SourceCodester Best Salon Management System 1.0. Th...
CVE-2025-6605HIGH8.8A vulnerability classified as critical was found in SourceCodester Best Salon Management System 1.0. This vulnerability ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now