2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-6967HIGH8.7Execution After Redirect (EAR) vulnerability in Sarman Soft Software and Technology Services Industry and Trade Ltd. Co....
CVE-2025-15570HIGH7.8A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file strea...
CVE-2025-15569HIGH7.3A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The impacted element is the function get_system_dpi of t...
CVE-2025-11537MEDIUM5A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre...
CVE-2025-40587HIGH7.6A vulnerability has been identified in Polarion V2404 (All versions < V2404.5), Polarion V2410 (All versions < V2410.2)....
CVE-2025-14895MEDIUM5.4The PopupKit plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.0. Thi...
CVE-2025-11242CRITICAL9.8Server-Side Request Forgery (SSRF) vulnerability in Teknolist Computer Systems Software Publishing Industry and Trade In...
CVE-2025-12063MEDIUM5.7An insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the...
CVE-2025-13064MEDIUM4.5A server-side injection was possible for a malicious admin to manipulate the application to include a malicious script w...
CVE-2025-12757MEDIUM4.6An AXIS Camera Station Pro feature can be exploited in a way that allows a non-admin user to view information they are n...
CVE-2025-11547HIGH7.8AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user.
CVE-2025-11142HIGH8.8The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code executio...
CVE-2025-15314HIGH8.1Tanium addressed an arbitrary file deletion vulnerability in end-user-cx.
CVE-2025-15313HIGH7.1Tanium addressed an arbitrary file deletion vulnerability in Tanium EUSS.
CVE-2025-15310HIGH7.8Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.
CVE-2025-15147MEDIUM4.3The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure...
CVE-2025-15319HIGH7.8Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.
CVE-2025-15318MEDIUM6Tanium addressed an arbitrary file deletion vulnerability in End-User Notifications Endpoint Tools.
CVE-2025-15317MEDIUM6.5Tanium addressed an uncontrolled resource consumption vulnerability in Tanium Server.
CVE-2025-15316HIGH7.8Tanium addressed a local privilege escalation vulnerability in Tanium Server.
CVE-2025-15315HIGH7.8Tanium addressed a local privilege escalation vulnerability in Tanium Module Server.
CVE-2025-14778MEDIUM5.4A flaw was found in Keycloak. A significant Broken Access Control vulnerability exists in the UserManagedPermissionServi...
CVE-2025-7432LOW1DPA countermeasures in Silicon Labs' Series 2 devices are not reseeded under certain conditions.  This may allow an att...
CVE-2025-66630CRITICAL9.4Fiber is an Express inspired web framework written in Go. Before 2.52.11, on Go versions prior to 1.24, the underlying c...
CVE-2025-63354MEDIUM4.8Hitron HI3120 v7.2.4.5.2b1 allows stored XSS via the Parental Control option when creating a new filter. The device fail...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now