2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-15322MEDIUM4.3Tanium addressed an improper access controls vulnerability in Tanium Server.
CVE-2025-15288MEDIUM4.3Tanium addressed an improper access controls vulnerability in Interact.
CVE-2025-69929CRITICAL9.8An issue in N3uron Web User Interface v.1.21.7-240207.1047 allows a remote attacker to escalate privileges via the passw...
CVE-2025-69604HIGH7.8An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to in...
CVE-2025-69516HIGH8.8A Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware Tactica...
CVE-2025-63658HIGH7.5A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to...
CVE-2025-63657HIGH7.5An out-of-bounds read in the mk_mimetype_find function (mk_server/mk_mimetype.c) of monkey commit f37e984 allows attacke...
CVE-2025-63656HIGH7.5An out-of-bounds read in the header_cmp function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers ...
CVE-2025-63655HIGH7.5A NULL pointer dereference in the mk_http_range_parse function (mk_server/mk_http.c) of monkey commit f37e984 allows att...
CVE-2025-63653HIGH7.5An out-of-bounds read in the mk_vhost_fdt_close function (mk_server/mk_vhost.c) of monkey commit f37e984 allows attacker...
CVE-2025-63652HIGH7.5A use-after-free in the mk_http_request_end function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to ...
CVE-2025-63651HIGH7.5A use-after-free in the mk_string_char_search function (mk_core/mk_string.c) of monkey commit f37e984 allows attackers t...
CVE-2025-63650HIGH7.5An out-of-bounds read in the mk_ptr_to_buf in mk_core function (mk_memory.c) of monkey commit f37e984 allows attackers t...
CVE-2025-63649HIGH7.5An out-of-bounds read in the http_parser_transfer_encoding_chunked function (mk_server/mk_http_parser.c) of monkey commi...
CVE-2025-15550MEDIUM5.3birkir prime <= 0.4.0.beta.0 contains a cross-site request forgery vulnerability in its GraphQL endpoint that allows att...
CVE-2025-15549MEDIUM4.8FluentCMS 2026 contains a stored cross-site scripting vulnerability that allows authenticated administrators to upload S...
CVE-2025-69749MEDIUM6.1Cross Site Scripting vulnerability in tale v.2.0.5 allows an attacker to execute arbitrary code.
CVE-2025-15548MEDIUM6.5Some VX800v v1.0 web interface endpoints transmit sensitive information over unencrypted HTTP due to missing application...
CVE-2025-15543MEDIUM4.6Improper link resolution in USB HTTP access path in VX800v v1.0 allows a crafted USB device to expose root filesystem co...
CVE-2025-15542MEDIUM5.3Improper handling of exceptional conditions in VX800v v1.0 in SIP processing allows an attacker to flood the device with...
CVE-2025-15541MEDIUM6.3Improper link resolution in the VX800v v1.0 SFTP service allows authenticated adjacent attackers to use crafted symbolic...
CVE-2025-13399HIGH8.8A weakness in the web interface’s application layer encryption in VX800v v1.0 allows an adjacent attacker to brute force...
CVE-2025-45160MEDIUM5.4A HTML injection vulnerability exists in the file upload functionality of Cacti <= 1.2.29. When a file with an invalid f...
CVE-2025-15545MEDIUM6.8The backup restore function does not properly validate unexpected or unrecognized tags within the backup file. When such...
CVE-2025-71011MEDIUM6.2An input validation vulnerability in the flow.Tensor.new_empty/flow.Tensor.new_ones/flow.Tensor.new_zeros component of O...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now