2025 CVE Vulnerabilities

45,279 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-2409CRITICAL9.1File corruption vulnerabilities in ASPECT provide attackers access to overwrite sys-tem files if session administrator c...
CVE-2025-48061MEDIUM5.6wire-webapp is the web application for the open-source messaging service Wire. A change caused a regression resulting in...
CVE-2025-47780HIGH7.8Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Aste...
CVE-2025-47779MEDIUM6.5Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Aste...
CVE-2025-46716MEDIUM5.5Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in ve...
CVE-2025-46715HIGH7.8Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in ve...
CVE-2025-45472HIGH8.8Insecure permissions in autodeploy-layer v1.2.0 allows attackers to escalate privileges and compromise the customer clou...
CVE-2025-43596CRITICAL9.8An insecure file system permissions vulnerability in MSP360 Backup 8.0 allows a low privileged user to execute commands ...
CVE-2025-33138MEDIUM6.1IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML co...
CVE-2025-33137HIGH8.8IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unau...
CVE-2025-33136HIGH8.8IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unau...
CVE-2025-5081CRITICAL9.8A vulnerability classified as critical was found in Campcodes Cybercafe Management System 1.0. Affected by this vulnerab...
CVE-2025-4366MEDIUM6.1A request smuggling vulnerability identified within Pingora’s proxying framework, pingora-proxy, allows malicious HTTP r...
CVE-2025-45468HIGH8.8Insecure permissions in fc-stable-diffusion-plus v1.0.18 allows attackers to escalate privileges and compromise the cust...
CVE-2025-2506MEDIUM5.3When pglogical attempts to replicate data, it does not verify it is using a replication connection, which means a user w...
CVE-2025-23183MEDIUM6.1CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
CVE-2025-23182MEDIUM4.3CWE-203: Observable Discrepancy
CVE-2025-5080HIGH8.8A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function webExcptypemanFil...
CVE-2025-5079CRITICAL9.8A flaw has been found in PHPGurukul/Campcodes Online Shopping Portal 1.0. Affected by this vulnerability is an unknown f...
CVE-2025-5024HIGH7.4A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated atta...
CVE-2025-45471HIGH8.8Insecure permissions in measure-cold-start v1.4.1 allows attackers to escalate privileges and compromise the customer cl...
CVE-2025-32915MEDIUM5.5Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2....
CVE-2025-32815MEDIUM6.5An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.
CVE-2025-32814CRITICAL9.8An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.
CVE-2025-32813HIGH7.2An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now