2025 CVE Vulnerabilities

45,294 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-4301CRITICAL9.8A vulnerability classified as critical was found in itsourcecode Content Management System 1.0. Affected by this vulnera...
CVE-2025-46728HIGH7.5cpp-httplib is a C++ header-only HTTP/HTTPS server and client library. Prior to version 0.20.1, the library fails to enf...
CVE-2025-2509HIGH7.8Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address acc...
CVE-2025-4300CRITICAL9.8A vulnerability classified as critical has been found in itsourcecode Content Management System 1.0. Affected is an unkn...
CVE-2025-4299CRITICAL9.8A vulnerability was found in Tenda AC1206 up to 15.03.06.23. It has been rated as critical. This issue affects the funct...
CVE-2025-4298CRITICAL9.8A vulnerability was found in Tenda AC1206 up to 15.03.06.23. It has been declared as critical. This vulnerability affect...
CVE-2025-4297CRITICAL9.8A vulnerability was found in PHPGurukul Men Salon Management System 2.0. It has been classified as critical. This affect...
CVE-2025-4293MEDIUM5.4A vulnerability was found in MRCMS 3.1.3 and classified as problematic. Affected by this issue is some unknown functiona...
CVE-2025-4292MEDIUM5.4A vulnerability has been found in MRCMS 3.1.3 and classified as problematic. Affected by this vulnerability is an unknow...
CVE-2025-4291CRITICAL9.8A vulnerability, which was classified as critical, was found in IdeaCMS up to 1.6. Affected is the function saveUpload. ...
CVE-2025-4290CRITICAL9.8A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unk...
CVE-2025-44074CRITICAL9.8SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_topic.php.
CVE-2025-44072CRITICAL9.8SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_manager.php.
CVE-2025-44071CRITICAL9.8SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php. This ...
CVE-2025-4289CRITICAL9.8A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. This vulnerability affects unknown code of t...
CVE-2025-4288CRITICAL9.8A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the com...
CVE-2025-1493MEDIUM5.3IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 12.1.0 through 12.1.1 could allow an authenticat...
CVE-2025-1000MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 coul...
CVE-2025-0915MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 un...
CVE-2025-4287MEDIUM4.8A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the functi...
CVE-2025-4286MEDIUM4.9A vulnerability was found in Intelbras InControl up to 2.21.59. It has been classified as problematic. Affected is an un...
CVE-2025-46813HIGH7.5Discourse is an open-source community platform. A data leak vulnerability affects sites deployed between commits 10df7fd...
CVE-2025-46734MEDIUM6.4league/commonmark is a PHP Markdown parser. A cross-site scripting (XSS) vulnerability in the Attributes extension of th...
CVE-2025-46731HIGH7.2Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch pri...
CVE-2025-46730MEDIUM6.5MobSF is a mobile application security testing tool used. Typically, MobSF is deployed on centralized internal or cloud-...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now