2025 CVE Vulnerabilities

45,277 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-48472HIGH8.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, there is no check to ensure that...
CVE-2025-48471CRITICAL9.8FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, the application does not check o...
CVE-2025-48390HIGH7.2FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to code ...
CVE-2025-48389HIGH7.2FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to deser...
CVE-2025-45474HIGH7.3maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings.
CVE-2025-3913LOW3.8Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly validate pe...
CVE-2025-5334HIGH7.5Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Des...
CVE-2025-5321CRITICAL9.9A vulnerability classified as critical was found in aimhubio aim up to 3.29.1. This vulnerability affects the function R...
CVE-2025-4081MEDIUM4.8Use of entitlement "com.apple.security.cs.disable-library-validation" and lack of launch and library load constraints al...
CVE-2025-48748CRITICAL10Netwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password.
CVE-2025-5320MEDIUM6.3A vulnerability classified as problematic has been found in gradio-app gradio up to 5.29.1. This affects the function is...
CVE-2025-46080MEDIUM5.3HuoCMS V3.5.1 has a File Upload Vulnerability. An attacker can exploit this flaw to bypass whitelist restrictions and cr...
CVE-2025-46078MEDIUM5.3HuoCMS V3.5.1 and before is vulnerable to file upload, which allows attackers to take control of the target server
CVE-2025-37999MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs/erofs/fileio: call erofs_onlinefolio_split() aft...
CVE-2025-37998MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: openvswitch: Fix unsafe attribute parsing in output...
CVE-2025-37997MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix region locking in hash types ...
CVE-2025-37996MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix uninitialized memcache pointer in u...
CVE-2025-37995MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: module: ensure that kobject_put() is safe for modul...
CVE-2025-37994MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: displayport: Fix NULL pointer acc...
CVE-2025-37993MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: can: m_can: m_can_class_allocate_dev(): initialize ...
CVE-2025-33043MEDIUM6.1APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation locally. Successful exp...
CVE-2025-48047CRITICAL9.4An authenticated user can perform command injection via unsanitized input to the NetFax Server’s ping functionality via ...
CVE-2025-48046MEDIUM5.3An authenticated user can disclose the cleartext password of a configured SMTP server via an HTTP GET request to the /co...
CVE-2025-48045HIGH8.7An unauthenticated HTTP GET request to the /client.php endpoint will disclose the default administrator user credentials...
CVE-2025-48388MEDIUM6.5FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the application performs insuffi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now