2025 CVE Vulnerabilities

45,266 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-52876MEDIUM5.4In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible
CVE-2025-52875MEDIUM5.4In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible
CVE-2025-48700MEDIUM6.1An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vul...
CVE-2025-46101CRITICAL9.8SQL Injection vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Reference Model...
CVE-2025-52542Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-2172MEDIUM6.6Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the inp...
CVE-2025-2171HIGH7.8Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attem...
CVE-2025-6513CRITICAL9.3Standard Windows users can access the configuration file for database access of the BRAIN2 application and decrypt it.
CVE-2025-6512CRITICAL10On a client with a non-admin user, a script can be integrated into a report. The reports could later be executed on the ...
CVE-2025-52922HIGH7.4Innoshop through 0.4.1 allows directory traversal via FileManager API endpoints. An authenticated attacker with access t...
CVE-2025-52921CRITICAL9.9In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achi...
CVE-2025-52920MEDIUM6.4Innoshop through 0.4.1 allows Insecure Direct Object Reference (IDOR) at multiple places within the frontend shop. Anyon...
CVE-2025-23049HIGH8.4Meridian Technique Materialise OrthoView through 7.5.1 allows OS Command Injection when servlet sharing is enabled.
CVE-2025-52939CRITICAL9.4Out-of-bounds Write vulnerability in dail8859 NotepadNext (src/lua/src modules). This vulnerability is associated with p...
CVE-2025-52938MEDIUM5.1Out-of-bounds Read vulnerability in dail8859 NotepadNext (src/lua/src modules). This vulnerability is associated with pr...
CVE-2025-52937LOW2Vulnerability in PointCloudLibrary PCL (surface/src/3rdparty/opennurbs modules). This vulnerability is associated with p...
CVE-2025-52936CRITICAL9.3Improper Link Resolution Before File Access ('Link Following') vulnerability in yrutschle sslh.This issue affects sslh: ...
CVE-2025-52935CRITICAL9.4Integer Overflow or Wraparound vulnerability in dragonflydb dragonfly (src/redis/lua/struct modules). This vulnerability...
CVE-2025-27387HIGH7.4OPPO Clone Phone uses a weak password WiFi hotspot to transfer files, resulting in Information disclosure.
CVE-2025-6503CRITICAL9.8A vulnerability was found in code-projects Inventory Management System 1.0 and classified as critical. This issue affect...
CVE-2025-6502CRITICAL9.8A vulnerability has been found in code-projects Inventory Management System 1.0 and classified as critical. This vulnera...
CVE-2025-6501CRITICAL9.8A vulnerability, which was classified as critical, was found in code-projects Inventory Management System 1.0. This affe...
CVE-2025-6500CRITICAL9.8A vulnerability, which was classified as critical, has been found in code-projects Inventory Management System 1.0. Affe...
CVE-2025-6499MEDIUM5.5A vulnerability classified as problematic was found in vstakhov libucl up to 0.9.2. Affected by this vulnerability is th...
CVE-2025-6498MEDIUM5.5A vulnerability classified as problematic has been found in HTACG tidy-html5 5.8.0. Affected is the function defaultAllo...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now