2025 CVE Vulnerabilities

45,268 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-6006HIGH7.2A vulnerability, which was classified as critical, has been found in kiCode111 like-girl 5.2.0. This issue affects some ...
CVE-2025-6005HIGH7.2A vulnerability classified as critical was found in kiCode111 like-girl 5.2.0. This vulnerability affects unknown code o...
CVE-2025-32466MEDIUM6.7A SQL injection vulnerability in RSMediaGallery! component 1.7.4 - 2.1.7 for Joomla was discovered. The issue occurs wit...
CVE-2025-32465HIGH8.5A stored XSS vulnerability in RSTickets! component 1.9.12 - 3.3.0 for Joomla was discovered. It allows attackers to perf...
CVE-2025-30085CRITICAL9.2Remote code execution vulnerability in RSForm!pro component 3.0.0 - 3.3.14 for Joomla was discovered. The issue occurs w...
CVE-2025-49150MEDIUM5.9Cursor is a code editor built for programming with AI. Prior to 0.51.0, by default, the setting json.schemaDownload.enab...
CVE-2025-40912CRITICAL9.8CryptX for Perl before version 0.065 contains a dependency that may be susceptible to malformed unicode. CryptX embeds ...
CVE-2025-25032HIGH7.5IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 could allow an a...
CVE-2025-0923MEDIUM5.3IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 stores source co...
CVE-2025-0917MEDIUM4.8IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to...
CVE-2025-0913MEDIUM5.5os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a danglin...
CVE-2025-6002HIGH7.2An unrestricted file upload vulnerability exists in the Product Image section of the VirtueMart backend. Authenticated a...
CVE-2025-6001HIGH8.3A Cross-Site Request Forgery (CSRF) vulnerability exists in the product image upload function of VirtueMart that bypasse...
CVE-2025-4673MEDIUM6.8Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive inf...
CVE-2025-40915HIGH7Mojolicious::Plugin::CSRF 1.03 for Perl uses a weak random number source for generating CSRF tokens. That version of th...
CVE-2025-22874HIGH7.5Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. Th...
CVE-2025-1699LOW2.8An incorrect default permissions vulnerability was reported in the MotoSignature application that could result in unauth...
CVE-2025-1698LOW2.8Null pointer exception vulnerabilities were reported in the fingerprint sensor service that could allow a local attacker...
CVE-2025-26383MEDIUM6.3The iSTAR Configuration Utility (ICU) tool leaks memory, which could result in the unintended exposure of unauthorized d...
CVE-2025-49148HIGH7.3ClipShare is a lightweight and cross-platform tool for clipboard sharing. Prior to 3.8.5, ClipShare Server for Windows u...
CVE-2025-49146MEDIUM5.9pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is config...
CVE-2025-48448MEDIUM6.5Allocation of Resources Without Limits or Throttling vulnerability in Drupal Admin Audit Trail allows Excessive Allocati...
CVE-2025-48447HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Lightgaller...
CVE-2025-48446HIGH8.8Incorrect Authorization vulnerability in Drupal Commerce Alphabank Redirect allows Functionality Misuse.This issue affec...
CVE-2025-48445HIGH8.8Incorrect Authorization vulnerability in Drupal Commerce Eurobank (Redirect) allows Functionality Misuse.This issue affe...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now