2025 CVE Vulnerabilities

45,323 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-26385CRITICAL9.5Johnson Controls Metasys component listed below have Improper Neutralization of Special Elements used in a Command (Com...
CVE-2025-1395HIGH8.2Generation of Error Message Containing Sensitive Information vulnerability in Codriapp Innovation and Software Technolog...
CVE-2025-12899MEDIUM6.5A flaw in Zephyr’s network stack allows an IPv4 packet containing ICMP type 128 to be misclassified as an ICMPv6 Echo Re...
CVE-2025-15322MEDIUM4.3Tanium addressed an improper access controls vulnerability in Tanium Server.
CVE-2025-15288MEDIUM4.3Tanium addressed an improper access controls vulnerability in Interact.
CVE-2025-69929CRITICAL9.8An issue in N3uron Web User Interface v.1.21.7-240207.1047 allows a remote attacker to escalate privileges via the passw...
CVE-2025-69604HIGH7.8An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to in...
CVE-2025-69516HIGH8.8A Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware Tactica...
CVE-2025-63658HIGH7.5A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to...
CVE-2025-63657HIGH7.5An out-of-bounds read in the mk_mimetype_find function (mk_server/mk_mimetype.c) of monkey commit f37e984 allows attacke...
CVE-2025-63656HIGH7.5An out-of-bounds read in the header_cmp function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers ...
CVE-2025-63655HIGH7.5A NULL pointer dereference in the mk_http_range_parse function (mk_server/mk_http.c) of monkey commit f37e984 allows att...
CVE-2025-63653HIGH7.5An out-of-bounds read in the mk_vhost_fdt_close function (mk_server/mk_vhost.c) of monkey commit f37e984 allows attacker...
CVE-2025-63652HIGH7.5A use-after-free in the mk_http_request_end function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to ...
CVE-2025-63651HIGH7.5A use-after-free in the mk_string_char_search function (mk_core/mk_string.c) of monkey commit f37e984 allows attackers t...
CVE-2025-63650HIGH7.5An out-of-bounds read in the mk_ptr_to_buf in mk_core function (mk_memory.c) of monkey commit f37e984 allows attackers t...
CVE-2025-63649HIGH7.5An out-of-bounds read in the http_parser_transfer_encoding_chunked function (mk_server/mk_http_parser.c) of monkey commi...
CVE-2025-15550MEDIUM5.3birkir prime <= 0.4.0.beta.0 contains a cross-site request forgery vulnerability in its GraphQL endpoint that allows att...
CVE-2025-15549MEDIUM4.8FluentCMS 2026 contains a stored cross-site scripting vulnerability that allows authenticated administrators to upload S...
CVE-2025-69749MEDIUM6.1Cross Site Scripting vulnerability in tale v.2.0.5 allows an attacker to execute arbitrary code.
CVE-2025-15548MEDIUM6.5Some VX800v v1.0 web interface endpoints transmit sensitive information over unencrypted HTTP due to missing application...
CVE-2025-15543MEDIUM4.6Improper link resolution in USB HTTP access path in VX800v v1.0 allows a crafted USB device to expose root filesystem co...
CVE-2025-15542MEDIUM5.3Improper handling of exceptional conditions in VX800v v1.0 in SIP processing allows an attacker to flood the device with...
CVE-2025-15541MEDIUM6.3Improper link resolution in the VX800v v1.0 SFTP service allows authenticated adjacent attackers to use crafted symbolic...
CVE-2025-13399HIGH8.8A weakness in the web interface’s application layer encryption in VX800v v1.0 allows an adjacent attacker to brute force...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now