2025 CVE Vulnerabilities

45,322 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-15311HIGH7.8Tanium addressed an unauthorized code execution vulnerability in Tanium Appliance.
CVE-2025-15289LOW3.1Tanium addressed an improper access controls vulnerability in Interact.
CVE-2025-70073HIGH7.2An issue in ChestnutCMS v.1.5.8 and before allows a remote attacker to execute arbitrary code via the template creation ...
CVE-2025-68121CRITICAL10During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between th...
CVE-2025-58190MEDIUM5.3The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can ...
CVE-2025-47911MEDIUM5.3The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which ...
CVE-2025-15557HIGH8.8An Improper Certificate Validation vulnerability in TP-Link Tapo H100 v1 and Tapo P100 v1 allows an on-path attacker on ...
CVE-2025-15551MEDIUM5.6The response coming from TP-Link Archer MR200 v5.2, C20 v5 and v6, TL-WR850N v3, and TL-WR845N v4 for any request is get...
CVE-2025-70792MEDIUM6.1Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipu...
CVE-2025-70791MEDIUM6.1Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipu...
CVE-2025-69906HIGH8.8Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies o...
CVE-2025-69619MEDIUM5.5A path traversal in My Text Editor v1.6.2 allows attackers to cause a Denial of Service (DoS) via writing files to the i...
CVE-2025-68723CRITICAL9Axigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin in...
CVE-2025-68643MEDIUM5.4Axigen Mail Server before 10.5.57 allows stored Cross-Site Scripting (XSS) in the handling of the timeFormat account pre...
CVE-2025-68722HIGH8.8Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability i...
CVE-2025-68721HIGH8.1Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface. A delegat...
CVE-2025-14150MEDIUM6.5IBM webMethods Integration (on prem) - Integration Server 10.15 through IS_10.15_Core_Fix2411.1 to IS_11.1_Core_Fix8 IBM...
CVE-2025-13491MEDIUM5.1IBM App Connect Enterprise Certified Container CD: 11.2.0 through 11.6.0, 12.1.0 through 12.19.0 and 12.0 LTS: 12.0.0 th...
CVE-2025-13379HIGH8.6IBM Aspera Console 3.4.0 through 3.4.8 is vulnerable to SQL injection. A remote attacker could send specially crafted SQ...
CVE-2025-14079MEDIUM5.3The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Missing Authorization in a...
CVE-2025-13416MEDIUM4.3The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized user suspensi...
CVE-2025-10258MEDIUM6.3Infinera DNA is vulnerable to a time-based SQL injection vulnerability due to insufficient input validation, which may r...
CVE-2025-15080HIGH8.8Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric MELSEC iQ-R Series R08PCPU, R16P...
CVE-2025-61732HIGH8.6A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.
CVE-2025-10314HIGH8.8Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation FREQSHIP-mini for Windows versions 8.0.0 ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now