2025 CVE Vulnerabilities

45,280 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-1948HIGH7.5In Eclipse Jetty versions 12.0.0 to 12.0.16 included, an HTTP/2 client can specify a very large value for the HTTP/2 set...
CVE-2025-44021LOW2.8OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment w...
CVE-2025-26847HIGH7.5An issue was discovered in Znuny before 7.1.5. When generating a support bundle, not all passwords are masked.
CVE-2025-26845CRITICAL9.8An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the configuration file can us...
CVE-2025-4132Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-45847MEDIUM6.5ALFA AIP-W512 v3.2.2.2.3 was discovered to contain an authenticated stack overflow via the targetAPMac parameter in the ...
CVE-2025-45846HIGH8.8ALFA AIP-W512 v3.2.2.2.3 was discovered to contain an authenticated stack overflow via the torrentsindex parameter in th...
CVE-2025-45845HIGH8.8TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g paramet...
CVE-2025-45844HIGH8.8TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter...
CVE-2025-45843HIGH8.8TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter...
CVE-2025-45842HIGH8.8TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g paramet...
CVE-2025-45841CRITICAL9.8TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the text parameter...
CVE-2025-43926MEDIUM6.1An issue was discovered in Znuny through 6.5.14 and 7.x through 7.1.6. Custom AJAX calls to the AgentPreferences UpdateA...
CVE-2025-26844CRITICAL9.8An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag.
CVE-2025-26842HIGH7.5An issue was discovered in Znuny through 7.1.3. If access to a ticket is not given, the content of S/MIME encrypted e-ma...
CVE-2025-4207MEDIUM5.9Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial ...
CVE-2025-45820MEDIUM6.5Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/bibliography/p...
CVE-2025-45819MEDIUM6.5Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/au...
CVE-2025-45818MEDIUM6.5Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/it...
CVE-2025-47730HIGH7.5The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM ...
CVE-2025-47729MEDIUM4.9The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal...
CVE-2025-4208MEDIUM6.3The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Limited Code E...
CVE-2025-3862MEDIUM5.4Contest Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions...
CVE-2025-3506MEDIUM5.3Files to be deployed with agents are accessible without authentication in Checkmk 2.1.0, Checkmk 2.2.0, Checkmk 2.3.0 an...
CVE-2025-3468MEDIUM5.4The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Stored Cross-S...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now