2025 CVE Vulnerabilities

45,267 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-23170MEDIUM6.7The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the ...
CVE-2025-23169MEDIUM6.1The Versa Director SD-WAN orchestration platform allows customization of the user interface, including the header, foote...
CVE-2025-23168HIGH8.8The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OT...
CVE-2025-23121HIGH8.8A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user
CVE-2025-49591CRITICAL9.1CryptPad is a collaboration suite. Prior to version 2025.3.0, enforcement of Two-Factor Authentication (2FA) in CryptPad...
CVE-2025-49590MEDIUM6.1CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javasc...
CVE-2025-26199CRITICAL9.8CloudClassroom-PHP-Project v1.0 is affected by an insecure credential transmission vulnerability. The application transm...
CVE-2025-6192HIGH8.8Use after free in Metrics in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially exploit heap...
CVE-2025-6191HIGH8.8Integer overflow in V8 in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially perform out of ...
CVE-2025-29646HIGH7.1An issue in upf in open5gs 2.7.2 and earlier allows a remote attacker to cause a Denial of Service via a crafted PFCP Se...
CVE-2025-26198CRITICAL9.8CloudClassroom-PHP-Project v1.0 contains a critical SQL Injection vulnerability in the loginlinkadmin.php component. The...
CVE-2025-20260CRITICAL9.8A vulnerability in the PDF scanning processes of ClamAV could allow an unauthenticated, remote attacker to cause a buffe...
CVE-2025-20271HIGH8.6A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devic...
CVE-2025-20234HIGH7.5A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to c...
CVE-2025-1349MEDIUM4.8IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulne...
CVE-2025-1348MEDIUM4IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 could allo...
CVE-2025-4821HIGH7.5Impact Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to...
CVE-2025-4820MEDIUM5.3Impact Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to...
CVE-2025-44952HIGH7.8A missing length check in `ogs_pfcp_subnet_add` function from PFCP library, used by both smf and upf in open5gs 2.7.2 an...
CVE-2025-44951HIGH7.1A missing length check in `ogs_pfcp_dev_add` function from PFCP library, used by both smf and upf in open5gs 2.7.2 and e...
CVE-2025-36049HIGH8.8IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE)...
CVE-2025-36048HIGH7.2IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 could allow a privileged user to escalate their privilege...
CVE-2025-6240MEDIUM4.9Improper Input Validation vulnerability in Profisee on Windows (filesystem modules) allows Path Traversal after authenti...
CVE-2025-46109HIGH8.8SQL Injection vulnerability in pbootCMS v.3.2.5 and v.3.2.10 allows a remote attacker to obtain sensitive information vi...
CVE-2025-45786HIGH8.1Real Estate Management 1.0 is vulnerable to Cross Site Scripting (XSS) in /store/index.php.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now