2025 CVE Vulnerabilities

45,279 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-47706MEDIUM4.8Authentication Bypass by Capture-replay vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Remote Services w...
CVE-2025-47705MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal IFrame Remo...
CVE-2025-47704MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Klaro Cooki...
CVE-2025-47703MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Con...
CVE-2025-47702MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal oEmbed Prov...
CVE-2025-47701HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Drupal Restrict route by IP allows Cross Site Request Forgery.This is...
CVE-2025-44186MEDIUM5.4SourceCodester Best Employee Management System 1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/Operatio...
CVE-2025-44184MEDIUM4.8SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php vi...
CVE-2025-40595HIGH7.2A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. By...
CVE-2025-3932MEDIUM6.5It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attach...
CVE-2025-3909HIGH8.1Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the fil...
CVE-2025-3877Rejected reason: This CVE was marked as fixed, but due to other code landing - was not actually fixed. It was subsequen...
CVE-2025-3875HIGH7.5Thunderbird parses addresses in a way that can allow sender spoofing in case the server allows an invalid From address t...
CVE-2025-26785HIGH7.5An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 21...
CVE-2025-26784MEDIUM6.5An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 21...
CVE-2025-47782HIGH8.9motionEye is an online interface for the software motion, a video surveillance program with motion detection. In version...
CVE-2025-47781CRITICAL9.8Rallly is an open-source scheduling and collaboration tool. Versions up to and including 3.22.1 of the application featu...
CVE-2025-47778MEDIUM6.1Sulu is an open-source PHP content management system based on the Symfony framework. Starting in versions 2.5.21, 2.6.5,...
CVE-2025-47777CRITICAL9.65ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Versions prior to ...
CVE-2025-47775HIGH8.6Bullfrog is a GithHb Action to block unauthorized outbound traffic in GitHub workflows. Prior to version 0.8.4, using tc...
CVE-2025-24969MEDIUM5iTop is an web based IT Service Management tool. Prior to version 3.2.1, a portal user can see any other contacts pictur...
CVE-2025-24785MEDIUM4.3iTop is an web based IT Service Management tool. In version 3.2.0, an attacker may send a URL to the server to trigger a...
CVE-2025-24026MEDIUM5.3iTop is an web based IT Service Management tool. Versions prior to 3.2.1 are vulnerable to regular expression denial of ...
CVE-2025-24022HIGH8.5iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, server code execution is po...
CVE-2025-24021MEDIUM5iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account havi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now