2025 CVE Vulnerabilities

45,280 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-20190MEDIUM6.5A vulnerability in the lobby ambassador web interface of Cisco IOS XE Wireless Controller Software could allow an authen...
CVE-2025-20189HIGH7.4A vulnerability in the Cisco Express Forwarding functionality of Cisco IOS XE Software for Cisco ASR 903 Aggregation Ser...
CVE-2025-20188CRITICAL10A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client de...
CVE-2025-20187MEDIUM6.5A vulnerability in the application data endpoints of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could...
CVE-2025-20186HIGH8.8A vulnerability in the web-based management interface of the Wireless LAN Controller feature of Cisco IOS XE Software co...
CVE-2025-20182HIGH8.6A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol processing of Cisco Adaptive Security Appliance ...
CVE-2025-20181MEDIUM6.8A vulnerability in Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches could allow a...
CVE-2025-20164HIGH8.3A vulnerability in the Cisco Industrial Ethernet Switch Device Manager (DM) of Cisco IOS Software could allow an authent...
CVE-2025-20162HIGH8.6A vulnerability in the DHCP snooping security feature of Cisco IOS XE Software could allow an unauthenticated, remote at...
CVE-2025-20157MEDIUM5.9A vulnerability in certificate validation processing of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, co...
CVE-2025-20155MEDIUM6A vulnerability in the bootstrap loading of Cisco IOS XE Software could allow an authenticated, local attacker to write ...
CVE-2025-20154HIGH8.6A vulnerability in the Two-Way Active Measurement Protocol (TWAMP) server feature of Cisco IOS Software and Cisco IOS XE...
CVE-2025-20151MEDIUM4.3A vulnerability in the implementation of the Simple Network Management Protocol Version 3 (SNMPv3) feature of Cisco IOS ...
CVE-2025-20147MEDIUM5.4A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, c...
CVE-2025-20140HIGH7.4A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers (WLC...
CVE-2025-20137MEDIUM4.7A vulnerability in the access control list (ACL) programming of Cisco IOS Software that is running on Cisco Catalyst 100...
CVE-2025-20122HIGH7.8A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated...
CVE-2025-46551LOW3.7JRuby-OpenSSL is an add-on gem for JRuby that emulates the Ruby OpenSSL native library. Starting in JRuby-OpenSSL versio...
CVE-2025-46827MEDIUM5.4Graylog is a free and open log management platform. Prior to versions 6.0.14, 6.1.10, and 6.2.0, it is possible to obtai...
CVE-2025-47692MEDIUM4.3Missing Authorization vulnerability in contentstudio Contentstudio contentstudio allows Exploiting Incorrectly Configure...
CVE-2025-47691MEDIUM5.5Improper Control of Generation of Code ('Code Injection') vulnerability in Ultimate Member Ultimate Member ultimate-memb...
CVE-2025-47688CRITICAL9.8Missing Authorization vulnerability in Saad Iqbal Advanced File Manager file-manager-advanced allows Exploiting Incorrec...
CVE-2025-47686MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DELUCKS DELUCKS SE...
CVE-2025-47685HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Moloni Contribuinte Checkout contribuinte-checkout allows Stored XSS....
CVE-2025-47684MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Smaily Smaily for WP smaily-for-wp allows Cross Site Request Forgery....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now