2025 CVE Vulnerabilities

45,280 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-46826LOW1.3insa-auth is an authentication server for INSA Rouen. A minor issue allowed third-party websites to access the server's ...
CVE-2025-46821MEDIUM5.3Envoy is a cloud-native edge/middle/service proxy. Prior to versions 1.34.1, 1.33.3, 1.32.6, and 1.31.8, Envoy's URI tem...
CVE-2025-46265HIGH8.8On F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+) may b...
CVE-2025-43878HIGH8.3When running in Appliance mode, an authenticated attacker assigned the Administrator or Resource Administrator role may ...
CVE-2025-41433HIGH8.7When a Session Initiation Protocol (SIP) message routing framework (MRF) application layer gateway (ALG) profile is conf...
CVE-2025-41431HIGH8.7When connection mirroring is configured on a virtual server, undisclosed requests can cause the Traffic Management Micro...
CVE-2025-41414HIGH8.7When HTTP/2 client and server profile is configured on a virtual server, undisclosed requests can cause TMM to terminate...
CVE-2025-41399HIGH8.7When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can c...
CVE-2025-36557HIGH8.7When an HTTP profile with the Enforce RFC Compliance option is configured on a virtual server, undisclosed requests can ...
CVE-2025-36546CRITICAL9.2On an F5OS system, if the root user had previously configured the system to allow login via SSH key-based authentication...
CVE-2025-36525HIGH8.7When a BIG-IP APM virtual server is configured to use a PingAccess profile, undisclosed requests can cause TMM to termin...
CVE-2025-36504HIGH8.7When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses can cause an increase i...
CVE-2025-35995HIGH8.7When a BIG-IP PEM system is licensed with URL categorization, and the URL categorization policy or an iRule with the url...
CVE-2025-31644HIGH8.7When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS...
CVE-2025-4043MEDIUM6.8An admin user can gain unauthorized write access to the /etc/rc.local file on the device, which is executed on a system ...
CVE-2025-3925HIGH8.5BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 contain an execution...
CVE-2025-31177MEDIUM5.5gnuplot is affected by a heap buffer overflow at function utf8_copy_one.
CVE-2025-45514MEDIUM6.5Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.frmL7ImForm.
CVE-2025-45388MEDIUM6.1Wagtail CMS 6.4.1 is vulnerable to a Stored Cross-Site Scripting (XSS) in the document upload functionality. Attackers c...
CVE-2025-3476CRITICAL9.4Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager. The vulnerability could allows privilege e...
CVE-2025-3272MEDIUM6.7Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager.  The vulnerability could allow authentica...
CVE-2025-30147HIGH8.7Besu Native contains scripts and tooling that is used to build and package the native libraries used by the Ethereum cli...
CVE-2025-29746MEDIUM6.1Cross Site Scripting vulnerability in Koillection v.1.6.10 allows a remote attacker to escalate privileges via the colle...
CVE-2025-26169HIGH8.1IXON VPN Client before 1.4.4 on Windows allows Local Privilege Escalation to SYSTEM because there is code execution from...
CVE-2025-26168HIGH8.1IXON VPN Client before 1.4.4 on Linux and macOS allows Local Privilege Escalation to root because there is code executio...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now