2025 CVE Vulnerabilities

45,277 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-48928MEDIUM4The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent...
CVE-2025-48927MEDIUM5.3The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heap...
CVE-2025-48926HIGH7.5The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, ...
CVE-2025-48925HIGH7.5The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then...
CVE-2025-48746MEDIUM6.5Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authe...
CVE-2025-36572MEDIUM6.5Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image f...
CVE-2025-32802MEDIUM6.1Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. M...
CVE-2025-32801HIGH7.8Kea configuration and API directives can be used to load a malicious hook library. Many common configurations run Kea a...
CVE-2025-45343CRITICAL9.8An issue in Tenda W18E v.2.0 v.16.01.0.11 allows an attacker to execute arbitrary code via the editing functionality of ...
CVE-2025-3357CRITICAL9.8IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 19 could allow a remote attacker to execute arbitrary code du...
CVE-2025-5277CRITICAL9.6aws-mcp-server MCP server is vulnerable to command injection. An attacker can craft a prompt that once accessed by the M...
CVE-2025-4134HIGH7.3Lack of file validation in do_update_vps in Avast Business Antivirus for Linux 4.5 on Linux allows local user to spoof o...
CVE-2025-48734HIGH8.8Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2....
CVE-2025-45997HIGH8.6Sourcecodester Web-based Pharmacy Product Management System v.1.0 has a file upload vulnerability. An attacker can uploa...
CVE-2025-40651MEDIUM5.1Reflected Cross-Site Scripting (XSS) vulnerability in Real Easy Store. This vulnerability allows an attacker to execute ...
CVE-2025-4493MEDIUM6.5Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT req...
CVE-2025-5299HIGH7.3A vulnerability was found in SourceCodester Client Database Management System 1.0. It has been declared as critical. Thi...
CVE-2025-5298CRITICAL9.8A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. Affecte...
CVE-2025-5297MEDIUM6.6A vulnerability, which was classified as critical, has been found in SourceCodester Computer Store System 1.0. This issu...
CVE-2025-3864LOW2.3Hackney fails to properly release HTTP connections to the pool after handling 307 Temporary Redirect responses. Remote a...
CVE-2025-5295CRITICAL9.8A vulnerability classified as critical was found in FreeFloat FTP Server 1.0.0. This vulnerability affects unknown code ...
CVE-2025-40673MEDIUM5.3A Missing Authorization vulnerability has been found in DinoRANK. This vulnerability allows an attacker to access invoi...
CVE-2025-4963MEDIUM6.4The WP Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions u...
CVE-2025-1753HIGH7.8LLama-Index CLI version v0.12.20 contains an OS command injection vulnerability. The vulnerability arises from the impro...
CVE-2025-5287HIGH7.5The Likes and Dislikes Plugin plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all versio...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now