2025 CVE Vulnerabilities

45,279 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-5020MEDIUM4.3Opening maliciously-crafted URLs in Firefox from other apps such as Safari could have allowed attackers to spoof website...
CVE-2025-48069MEDIUM6.6ejson2env allows users to decrypt EJSON secrets and export them as environment variables. Prior to version 2.0.8, the `e...
CVE-2025-48064LOW3.3GitHub Desktop is an open-source, Electron-based GitHub app designed for git development. Prior to version 3.4.20-beta3,...
CVE-2025-48063HIGH8.8XWiki is a generic wiki platform. In XWiki 16.10.0, required rights were introduced as a way to limit which rights a doc...
CVE-2025-48060HIGH7.5jq is a command-line JSON processor. In versions up to and including 1.7.1, a heap-buffer-overflow is present in functio...
CVE-2025-47291HIGH7.5containerd is an open-source container runtime. A bug was found in the containerd's CRI implementation where containerd,...
CVE-2025-46822HIGH7.7OsamaTaher/Java-springboot-codebase is a collection of Java and Spring Boot code snippets, applications, and projects. P...
CVE-2025-2102MEDIUM5.7Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Passwordless on Windows allows Priv...
CVE-2025-5032CRITICAL9.8A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. Affected is an unknown fu...
CVE-2025-5031LOW3.1A vulnerability was found in Ackites KillWxapkg up to 2.4.1. It has been rated as problematic. This issue affects some u...
CVE-2025-5030HIGH8.1A vulnerability was found in Ackites KillWxapkg up to 2.4.1. It has been declared as critical. This vulnerability affect...
CVE-2025-4416HIGH7.5Allocation of Resources Without Limits or Throttling vulnerability in Drupal Events Log Track allows Excessive Allocatio...
CVE-2025-4415MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Piwik PRO a...
CVE-2025-48012MEDIUM4.8Authentication Bypass by Capture-replay vulnerability in Drupal One Time Password allows Remote Services with Stolen Cre...
CVE-2025-48011MEDIUM4.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality ...
CVE-2025-48010MEDIUM4.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality ...
CVE-2025-48009LOW3.1Missing Authorization vulnerability in Drupal Single Content Sync allows Functionality Misuse.This issue affects Single ...
CVE-2025-45754MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in SeedDMS 6.0.32. This vulnerability allows an attacker to inj...
CVE-2025-25539MEDIUM6.5Local File Inclusion vulnerability in Vasco v3.14and before allows a remote attacker to obtain sensitive information via...
CVE-2025-20267MEDIUM4.8A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat...
CVE-2025-20258MEDIUM5.4A vulnerability in the self-service portal of Cisco Duo could allow an unauthenticated, remote attacker to inject arbitr...
CVE-2025-20257MEDIUM6.5A vulnerability in an API subsystem of Cisco Secure Network Analytics Manager and Cisco Secure Network Analytics Virtual...
CVE-2025-20256HIGH7.2A vulnerability in the web-based management interface of Cisco Secure Network Analytics Manager and Cisco Secure Network...
CVE-2025-20255MEDIUM4.3A vulnerability in client join services of Cisco Webex Meetings could allow an unauthenticated, remote attacker to manip...
CVE-2025-20250MEDIUM6.1A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now