2025 CVE Vulnerabilities

45,279 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-47794MEDIUM4.3Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 29.0.13, 30.0.7, and 31.0.1 and Ne...
CVE-2025-47793MEDIUM6.5Nextcloud Server is a self hosted personal cloud system, and the Nextcloud Groupfolders app provides admin-configured fo...
CVE-2025-47792MEDIUM6.1Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3rdparty app...
CVE-2025-47791MEDIUM5.3Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 28.0.13, 29.0.10, and 30.0.3 and N...
CVE-2025-4780CRITICAL9.8A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been rated as critical. This issue ...
CVE-2025-4778HIGH8.8A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been declared as critical. This vul...
CVE-2025-4600HIGH7.5A request smuggling vulnerability existed in the Google Cloud Classic Application Load Balancer due to improper handling...
CVE-2025-4211HIGH7.3Improper Link Resolution Before File Access ('Link Following') vulnerability in QFileSystemEngine in the Qt corelib modu...
CVE-2025-47790MEDIUM6.4Nextcloud Server is a self hosted personal cloud system. Nextcloud Server prior to 29.0.15, 30.0.9, and 31.0.3 and Nextc...
CVE-2025-32962MEDIUM6.1Flask-AppBuilder is an application development framework built on top of Flask. Versions prior to 4.6.2 would allow for ...
CVE-2025-4777HIGH8.8A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been classified as critical. This a...
CVE-2025-4773CRITICAL9.8A vulnerability was found in PHPGurukul Online Course Registration 3.1 and classified as critical. Affected by this issu...
CVE-2025-40907MEDIUM5.3FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library. The in...
CVE-2025-40629HIGH8.7PNETLab 4.2.10 does not properly sanitize user inputs in its file access mechanisms. This allows attackers to perform di...
CVE-2025-37890HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Fix a UAF vulnerability in class w...
CVE-2025-2306MEDIUM5.9An Improper Access Control vulnerability was identified in the file download functionality. This vulnerability allows us...
CVE-2025-2305HIGH8.6A Path traversal vulnerability in the file download functionality was identified. This vulnerability allows unauthentica...
CVE-2025-4772CRITICAL9.8A vulnerability has been found in PHPGurukul Online Course Registration 3.1 and classified as critical. Affected by this...
CVE-2025-4771CRITICAL9.8A vulnerability, which was classified as critical, was found in PHPGurukul Online Course Registration 3.1. Affected is a...
CVE-2025-4770HIGH8.8A vulnerability, which was classified as critical, has been found in PHPGurukul Park Ticketing Management System 2.0. Th...
CVE-2025-4769HIGH7.3A vulnerability classified as critical was found in CBEWIN Anytxt Searcher 1.3.1128.0. This vulnerability affects unknow...
CVE-2025-40632MEDIUM6.1Cross-site scripting (XSS) in Icewarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to mod...
CVE-2025-40631MEDIUM6.1HTTP host header injection vulnerability in Icewarp Mail Server affecting version 11.4.0. By modifying the Host header a...
CVE-2025-40630MEDIUM6.1Open redirection vulnerability in IceWarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to...
CVE-2025-4768MEDIUM6.3A vulnerability classified as critical has been found in feng_ha_ha/megagao ssm-erp and production_ssm 1.0. This affects...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now