2025 CVE Vulnerabilities

45,267 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-6132CRITICAL9.8A vulnerability has been found in Chanjet CRM 1.0 and classified as critical. Affected by this vulnerability is an unkno...
CVE-2025-6179CRITICAL9.8Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a loca...
CVE-2025-6177HIGH7.4Privilege Escalation in MiniOS in Google ChromeOS (16063.45.2 and potentially others) on enrolled devices allows a local...
CVE-2025-6131MEDIUM4.8A vulnerability, which was classified as problematic, was found in CodeAstro Food Ordering System 1.0. Affected is an un...
CVE-2025-6130HIGH8.8A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This issue...
CVE-2025-5309CRITICAL9.8The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template I...
CVE-2025-2327MEDIUM5.1A flaw exists in FlashArray whereby the Key Encryption Key (KEK) is logged during key rotation when RDL is configured.
CVE-2025-6170LOW2.5A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inpu...
CVE-2025-6129HIGH8.8A vulnerability classified as critical was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This vulnerability affects ...
CVE-2025-6128HIGH8.8A vulnerability classified as critical has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This affects an unknow...
CVE-2025-49796CRITICAL9.1A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory ...
CVE-2025-49795HIGH7.5A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an...
CVE-2025-49794CRITICAL9.1A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circums...
CVE-2025-6127MEDIUM5.4A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been rated as problematic. Aff...
CVE-2025-6126MEDIUM5.4A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been declared as problematic. Affected b...
CVE-2025-4565MEDIUM5.3Any project that uses Protobuf Pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary numb...
CVE-2025-49125HIGH7.5Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat.  When using PreResources or Pos...
CVE-2025-49124HIGH8.4Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer fo...
CVE-2025-48988HIGH7.5Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: ...
CVE-2025-48976HIGH7.5Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons Fil...
CVE-2025-3594CRITICAL9.8Path traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal 7.0.0 through 7.4.3.4, a...
CVE-2025-3526HIGH7.5SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 2...
CVE-2025-6125MEDIUM5.4A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been classified as problematic. Affected...
CVE-2025-6124CRITICAL9.8A vulnerability was found in code-projects Restaurant Order System 1.0 and classified as critical. This issue affects so...
CVE-2025-3602HIGH7.5Liferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through update 92, 7.3 GA thr...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now