2025 CVE Vulnerabilities

45,266 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-48991MEDIUM4.3Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker could use a...
CVE-2025-48954MEDIUM6.1Discourse is an open-source discussion platform. Versions prior to 3.5.0.beta6 are vulnerable to cross-site scripting wh...
CVE-2025-6604HIGH8.8A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. This affects a...
CVE-2025-6543CRITICAL9.8Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Ga...
CVE-2025-25012MEDIUM5.4URL redirection to an untrusted site ('Open Redirect') in Kibana can lead to sending a user to an arbitrary site and ser...
CVE-2025-6603MEDIUM5.3A vulnerability was found in coldfunction qCUDA up to db0085400c2f2011eed46fbc04fdc0873141688e. It has been rated as pro...
CVE-2025-6613MEDIUM5.4A vulnerability classified as problematic was found in PHPGurukul Hospital Management System 4.0. Affected by this vulne...
CVE-2025-5927HIGH7.5The Everest Forms (Pro) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path vali...
CVE-2025-49797HIGH8.5Multiple Brother driver installers for Windows contain a privilege escalation vulnerability. If exploited, an arbitrary ...
CVE-2025-41647MEDIUM5.5A local, low-privileged attacker can learn the password of the connected controller in PLC Designer V4 due to an incorre...
CVE-2025-41256HIGH7.4Cyberduck and Mountain Duck improper handle TLS certificate pinning for untrusted certificates (e.g., self-signed), sinc...
CVE-2025-41255HIGH8Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates (e.g., self-signed), un...
CVE-2025-43880MEDIUM5.3Inefficient regular expression complexity issue exists in GROWI prior to v7.1.6. If exploited, a logged-in user may caus...
CVE-2025-5585MEDIUM5.4The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-url` DOM E...
CVE-2025-36004HIGH8.8IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user to gain elevated privileges due to an unqualified library call in IBM Fa...
CVE-2025-0966HIGH7.6IBM InfoSphere Information Server 11.7 vulnerable to SQL injection. A remote attacker could send specially crafted SQL s...
CVE-2025-6583HIGH8.8A vulnerability, which was classified as critical, was found in SourceCodester Best Salon Management System 1.0. This af...
CVE-2025-6582HIGH8.8A vulnerability, which was classified as critical, has been found in SourceCodester Best Salon Management System 1.0. Af...
CVE-2025-6581HIGH8.8A vulnerability classified as critical was found in SourceCodester Best Salon Management System 1.0. Affected by this vu...
CVE-2025-6580CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. Affected is an...
CVE-2025-52884LOW1.7RISC Zero is a zero-knowledge verifiable general computing platform, with Ethereum integration. The risc0-ethereum repos...
CVE-2025-52883MEDIUM5.3Meshtastic-Android is an Android application for the mesh radio software Meshtastic. Prior to version 2.5.21, an attacke...
CVE-2025-52572CRITICAL10Hikka, a Telegram userbot, has vulnerability affects all users on all versions of Hikka. Two scenarios are possible. 1. ...
CVE-2025-6579CRITICAL9.8A vulnerability was found in code-projects Car Rental System 1.0. It has been rated as critical. This issue affects some...
CVE-2025-6578CRITICAL9.8A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now