2025 CVE Vulnerabilities

45,268 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-41234MEDIUM6.5Description In Spring Framework, versions 6.0.x as of 6.0.5, versions 6.1.x and 6.2.x, an application is vulnerable to ...
CVE-2025-41233MEDIUM6.8Description: VMware AVI Load Balancer contains an authenticated blind SQL Injection vulnerability. VMware has evaluated...
CVE-2025-49589MEDIUM6.1PCSX2 is a free and open-source PlayStation 2 (PS2) emulator. A stack-based buffer overflow exists in the Kprintf_HLE fu...
CVE-2025-44091MEDIUM5.4yangyouwang crud v1.0.0 is vulnerable to Cross Site Scripting (XSS) via the role management function.
CVE-2025-27689HIGH7.8Dell iDRAC Tools, version(s) prior to 11.3.0.0, contain(s) an Improper Access Control vulnerability. A low privileged at...
CVE-2025-6031HIGH7.7Amazon Cloud Cam is a home security camera that was deprecated on December 2, 2022, is end of life, and is no longer act...
CVE-2025-5485HIGH8.8User names used to access the web management interface are limited to the device identifier, which is a numerical ident...
CVE-2025-5484HIGH8.3A username and password are required to authenticate to the central SinoTrack device management interface. The username...
CVE-2025-4418MEDIUM6.7An improper validation of integrity check value vulnerability exists in AVEVA PI Connector for CygNet Versions 1.6.14 ...
CVE-2025-4417MEDIUM6.9A cross-site scripting vulnerability exists in AVEVA PI Connector for CygNet Versions 1.6.14 and prior that, if exploi...
CVE-2025-48699Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and...
CVE-2025-44019HIGH7.1AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated...
CVE-2025-36539HIGH7.1AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticate...
CVE-2025-2745MEDIUM6.5A cross-site scripting vulnerability exists in AVEVA PI Web API version 2023 SP1 and prior that, if exploited, could al...
CVE-2025-49579MEDIUM4.8Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. All system messages in menu headings ...
CVE-2025-49578MEDIUM5.4Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various date messages returned by `La...
CVE-2025-49577MEDIUM5.4Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various preferences messages are inse...
CVE-2025-49576MEDIUM5.4Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The citizen-search-noresults-title an...
CVE-2025-49575MEDIUM5.4Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Multiple system messages are inserted...
CVE-2025-49081MEDIUM4.9There is an insufficient input validation vulnerability in the warehouse component of Absolute Secure Access prior to se...
CVE-2025-43866HIGH7.5vantage6 is an open-source infrastructure for privacy preserving analysis. The JWT secret key in the vantage6 server is ...
CVE-2025-43863CRITICAL9.8vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Le...
CVE-2025-5982HIGH7.5An issue has been discovered in GitLab EE affecting all versions from 12.0 before 17.10.8, 17.11 before 17.11.4, and 18....
CVE-2025-49080HIGH7.5There is a memory management vulnerability in Absolute Secure Access server versions 9.0 to 13.54. Attackers with networ...
CVE-2025-49467CRITICAL9.3A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered. The extension i...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now