2025 CVE Vulnerabilities

45,266 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-6557MEDIUM5.4Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker wh...
CVE-2025-6556MEDIUM5.4Insufficient policy enforcement in Loader in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to bypass co...
CVE-2025-6555MEDIUM5.4Use after free in Animation in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to potentially exploit hea...
CVE-2025-53021MEDIUM4.2A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions ...
CVE-2025-52888HIGH7.5Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. A critical XML External Entit...
CVE-2025-52882HIGH8.8Claude Code is an agentic coding tool. Claude Code extensions in VSCode and forks (e.g., Cursor, Windsurf, and VSCodium)...
CVE-2025-52880MEDIUM4.2Komga is a media server for comics, mangas, BDs, magazines and eBooks. A Cross-Site Scripting (XSS) vulnerability has be...
CVE-2025-52571CRITICAL9.6Hikka is a Telegram userbot. A vulnerability affects all users of versions below 1.6.2, including most of the forks. It ...
CVE-2025-52471CRITICAL9.8ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. An integer underflow vulnerability has been ide...
CVE-2025-49853CRITICAL9.3ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to SQL injections which could allow an attacke...
CVE-2025-49852HIGH8.7ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to a server-side request forgery vulnerability...
CVE-2025-49851CRITICAL9.8ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to an improper authentication vulnerability wh...
CVE-2025-5087MEDIUM6Kaleris NAVIS N4 ULC (Ultra Light Client) communicates insecurely using zlib-compressed data over HTTP. An attacker capa...
CVE-2025-2566CRITICAL9.3Kaleris NAVIS N4 ULC (Ultra Light Client) contains an unsafe Java deserialization vulnerability. An unauthenticated atta...
CVE-2025-53073MEDIUM4.2In Sentry 25.1.0 through 25.5.1, an authenticated attacker can access a project's issue endpoint and perform unauthorize...
CVE-2025-49147MEDIUM5.3Umbraco, a free and open source .NET content management system, has a vulnerability in versions 10.0.0 through 10.8.10 a...
CVE-2025-23260MEDIUM4.3NVIDIA AIStore contains a vulnerability in the AIS Operator where a user may gain elevated k8s cluster access by using t...
CVE-2025-4378CRITICAL10Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University ATA-A...
CVE-2025-6570HIGH8.8A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 4.0. Affected...
CVE-2025-50699MEDIUM6.1PHPGurukul Online DJ Booking Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in odms/admin/view-user-q...
CVE-2025-50695MEDIUM6.1PHPGurukul Online DJ Booking Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in /admin/view-booking-de...
CVE-2025-50693MEDIUM6.5PHPGurukul Online DJ Booking Management System 2.0 is vulnerable to Insecure Direct Object Reference (IDOR) in odms/requ...
CVE-2025-4383CRITICAL9.3Improper Restriction of Excessive Authentication Attempts vulnerability in Art-in Bilişim Teknolojileri ve Yazılım Hizm....
CVE-2025-44531HIGH7.5An issue in Realtek RTL8762EKF-EVB RTL8762E SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via sending a...
CVE-2025-23265HIGH7.8NVIDIA Megatron-LM for all platforms contains a vulnerability in a python component where an attacker may cause a code i...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now