2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-9820MEDIUM4A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 tok...
CVE-2025-9615LOW3.3A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. Ne...
CVE-2025-9522MEDIUM5.3Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests t...
CVE-2025-9521MEDIUM6.5Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypa...
CVE-2025-9520MEDIUM6.8An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate r...
CVE-2025-14969MEDIUM4.3A flaw was found in Hibernate Reactive. When an HTTP endpoint is exposed to perform database operations, a remote client...
CVE-2025-14525MEDIUM6.4A flaw was found in kubevirt. A user within a virtual machine (VM), if the guest agent is active, can exploit this by ca...
CVE-2025-14459HIGH8.5A flaw was found in KubeVirt Containerized Data Importer (CDI). This vulnerability allows a user to clone PersistentVolu...
CVE-2025-11687MEDIUM6.1A flaw was found in the gi-docgen. This vulnerability allows arbitrary JavaScript execution in the context of the page —...
CVE-2025-11065MEDIUM5.3A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode...
CVE-2025-70368MEDIUM5.4Worklenz version 2.1.5 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Project Updates feature. An att...
CVE-2025-14756HIGH8.8Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing...
CVE-2025-71178HIGH7.1Crucial Storage Executive installer versions prior to 11.08.082025.00 contain a DLL preloading vulnerability. During ins...
CVE-2025-57785MEDIUM6.5A Double Free in XSLT `show_index` has been identified in Hiawatha webserver version 11.7 which allows an unauthenticate...
CVE-2025-57784LOW3.3Tomahawk auth timing attack due to usage of `strcmp` has been identified in Hiawatha webserver version 11.7 which allows...
CVE-2025-57783MEDIUM5.3Improper header parsing may lead to request smuggling has been identified in Hiawatha webserver version 11.7 which allow...
CVE-2025-70982CRITICAL9.9Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to ...
CVE-2025-67274HIGH7.5An issue in continuous.software aangine v.2025.2 allows a remote attacker to obtain sensitive information via the excel-...
CVE-2025-50537MEDIUM5.5Stack overflow vulnerability in eslint before 9.26.0 when serializing objects with circular references in eslint/lib/sha...
CVE-2025-59109MEDIUM5.1The dormakaba registration units 9002 (PIN Pad Units) have an exposed UART header on the backside. The PIN pad is sendin...
CVE-2025-59108CRITICAL9.2By default, the password for the Access Manager's web interface, is set to 'admin'. In the tested version changing the p...
CVE-2025-59107HIGH8.5Dormakaba provides the software FWServiceTool to update the firmware version of the Access Managers via the network. The...
CVE-2025-59106HIGH8.8The binary serving the web server and executing basically all actions launched from the Web UI is running with root priv...
CVE-2025-59105HIGH7With physical access to the device and enough time an attacker can desolder the flash memory, modify it and then reinsta...
CVE-2025-59104HIGH7With physical access to the device and enough time an attacker is able to solder test leads to the debug footprint (or u...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now