2025 CVE Vulnerabilities

45,266 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-52558HIGH7changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification se...
CVE-2025-2828CRITICAL10A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community pa...
CVE-2025-23092HIGH7.2Mitel OpenScape Accounting Management through V5 R1.1.0 could allow an authenticated attacker with administrative privil...
CVE-2025-49574MEDIUM6.4Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. In versions prior to 3.24.1,...
CVE-2025-48026HIGH7.5A vulnerability in the WebApl component of Mitel OpenScape Xpressions through V7R1 FR5 HF43 P913 could allow an unauthen...
CVE-2025-44528HIGH7.5An issue in Texas Instruments LP-CC2652RB SimpleLink CC13XX CC26XX SDK 7.41.00.17 allows attackers to cause a Denial of ...
CVE-2025-6547CRITICAL9.1Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation.This issue affects pb...
CVE-2025-6545CRITICAL9.1Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability i...
CVE-2025-6518MEDIUM6.3A vulnerability was found in PySpur-Dev pyspur up to 0.1.18. It has been classified as critical. Affected is the functio...
CVE-2025-50349HIGH7.5PHPGurukul Pre-School Enrollment System Project V1.0 is vulnerable to Directory Traversal in update-teacher-pic.php.
CVE-2025-50348HIGH7.5PHPGurukul Pre-School Enrollment System Project V1.0 is vulnerable to Directory Traversal in update-class-pic.php.
CVE-2025-49144HIGH7.3Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerabilit...
CVE-2025-6517CRITICAL9.8A vulnerability was found in Dromara MaxKey up to 4.1.7 and classified as critical. This issue affects the function Add ...
CVE-2025-49126HIGH8.8Visionatrix is an AI Media processing tool using ComfyUI. In versions 1.5.0 to before 2.5.1, the /docs/flows endpoint is...
CVE-2025-6516HIGH7.8A vulnerability has been found in HDF5 up to 1.14.6 and classified as critical. This vulnerability affects the function ...
CVE-2025-6511HIGH8.8A vulnerability classified as critical has been found in Netgear EX6150 1.0.0.46_1.0.76. This affects the function sub_4...
CVE-2025-52969Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-6510HIGH8.8A vulnerability was found in Netgear EX6100 1.0.2.28_1.1.138. It has been rated as critical. Affected by this issue is t...
CVE-2025-6509LOW3.5A vulnerability was found in seaswalker spring-analysis up to 4379cce848af96997a9d7ef91d594aa129be8d71. It has been decl...
CVE-2025-4563LOW2.7A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation au...
CVE-2025-52968LOW2.7xdg-open in xdg-utils through 1.2.1 can send requests containing SameSite=Strict cookies, which can facilitate CSRF. (Fo...
CVE-2025-52967MEDIUM5.8gateway_proxy_handler in MLflow before 3.1.0 lacks gateway_path validation.
CVE-2025-52879MEDIUM4.8In JetBrains TeamCity before 2025.03.3 reflected XSS in the NPM Registry integration was possible
CVE-2025-52878MEDIUM4.3In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions
CVE-2025-52877MEDIUM4.8In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now