2025 CVE Vulnerabilities

45,267 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-49586HIGH8.8XWiki is an open-source wiki software platform. Any XWiki user with edit right on at least one App Within Minutes applic...
CVE-2025-49585HIGH8XWiki is a generic wiki platform. In versions before 15.10.16, 16.0.0-rc-1 through 16.4.6, and 16.5.0-rc-1 through 16.10...
CVE-2025-49584HIGH7.5XWiki is a generic wiki platform. In XWiki Platform versions 10.9 through 16.4.6, 16.5.0-rc-1 through 16.10.2, and 17.0....
CVE-2025-49583LOW3.5XWiki is a generic wiki platform. When a user without script right creates a document with an `XWiki.Notifications.Code....
CVE-2025-49582HIGH8XWiki is a generic wiki platform. When editing content that contains "dangerous" macros like malicious script macros tha...
CVE-2025-6052HIGH7.5A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, co...
CVE-2025-6035MEDIUM6.1A flaw was found in GIMP. An integer overflow vulnerability exists in the GIMP "Despeckle" plug-in. The issue occurs du...
CVE-2025-49581HIGH8.8XWiki is a generic wiki platform. Any user with edit right on a page (could be the user's profile) can execute code (Gro...
CVE-2025-49580HIGH8XWiki is a generic wiki platform. From 8.2 and 7.4.5 until 17.1.0-rc-1, 16.10.4, and 16.4.7, pages can gain script or pr...
CVE-2025-48920HIGH7.3Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal etracker al...
CVE-2025-48919MEDIUM5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klar...
CVE-2025-48918HIGH8.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klar...
CVE-2025-48917MEDIUM5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal EU Cookie C...
CVE-2025-48916MEDIUM6.5Missing Authorization vulnerability in Drupal Bookable Calendar allows Forceful Browsing.This issue affects Bookable Cal...
CVE-2025-48915HIGH8.6Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Con...
CVE-2025-48914HIGH8.6Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Con...
CVE-2025-6030CRITICAL9.4Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the Key Fob Transmitter in Cyc...
CVE-2025-6029CRITICAL9.4Use of fixed learning codes, one code to lock the car and the other code to unlock it, the Key Fob Transmitter in KIA-br...
CVE-2025-36633HIGH7.8In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrari...
CVE-2025-36631HIGH7.8In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite...
CVE-2025-28389CRITICAL9.8Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack.
CVE-2025-28388CRITICAL9.8OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.
CVE-2025-28386CRITICAL9.8A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers ...
CVE-2025-28384CRITICAL9.1An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory trav...
CVE-2025-28382HIGH7.5An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory travers...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now