2025 CVE Vulnerabilities

45,277 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-2501HIGH8.5An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate pr...
CVE-2025-1479MEDIUM5.3An open debug interface was reported in the Legion Space software included on certain Legion devices that could allow a ...
CVE-2025-5359CRITICAL9.8A vulnerability classified as critical has been found in Campcodes Online Hospital Management System 1.0. This affects a...
CVE-2025-48944MEDIUM6.5vLLM is an inference and serving engine for large language models (LLMs). In version 0.8.0 up to but excluding 0.9.0, th...
CVE-2025-48943MEDIUM6.5vLLM is an inference and serving engine for large language models (LLMs). Version 0.8.0 up to but excluding 0.9.0 have a...
CVE-2025-48942MEDIUM6.5vLLM is an inference and serving engine for large language models (LLMs). In versions 0.8.0 up to but excluding 0.9.0, h...
CVE-2025-48938CRITICAL9.8go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been id...
CVE-2025-48885MEDIUM5.7application-urlshortener create shortened URLs for XWiki pages. Versions prior to 1.2.4 are vulnerable to users with vie...
CVE-2025-48883MEDIUM5.3Chrome PHP allows users to start playing with chrome/chromium in headless mode from PHP. Prior to version 1.14.0, CSS Se...
CVE-2025-5358CRITICAL9.8A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been rated as critical. Affec...
CVE-2025-5357CRITICAL9.8A vulnerability was found in FreeFloat FTP Server 1.0. It has been declared as critical. Affected by this vulnerability ...
CVE-2025-5054MEDIUM4.7Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via ...
CVE-2025-48887MEDIUM6.5vLLM, an inference and serving engine for large language models (LLMs), has a Regular Expression Denial of Service (ReDo...
CVE-2025-5356CRITICAL9.8A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. Affected is an unknown functi...
CVE-2025-4992HIGH8.7A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in Service Process Engineer from Re...
CVE-2025-4991HIGH8.7A stored Cross-site Scripting (XSS) vulnerability affecting 3D Markup in Collaborative Industry Innovator from Release 3...
CVE-2025-4990HIGH8.7A stored Cross-site Scripting (XSS) vulnerability affecting Change Governance in Product Manager from Release 3DEXPERIEN...
CVE-2025-4989HIGH8.7A stored Cross-site Scripting (XSS) vulnerability affecting Requirements in Product Manager from Release 3DEXPERIENCE R2...
CVE-2025-4988HIGH8.7A stored Cross-site Scripting (XSS) vulnerability affecting Results Analytics in Multidisciplinary Optimization Engineer...
CVE-2025-4986HIGH8.7A stored Cross-site Scripting (XSS) vulnerability affecting Model Definition in Product Manager from Release 3DEXPERIENC...
CVE-2025-4985HIGH8.7A stored Cross-site Scripting (XSS) vulnerability affecting Risk Management in Project Portfolio Manager from Release 3D...
CVE-2025-4984HIGH8.7A stored Cross-site Scripting (XSS) vulnerability affecting City Discover in City Referential Manager on Release 3DEXPER...
CVE-2025-4983HIGH8.7A stored Cross-site Scripting (XSS) vulnerability affecting City Referential in City Referential Manager on Release 3DE...
CVE-2025-3611MEDIUM4.3Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restr...
CVE-2025-3230MEDIUM5.4Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now