2025 CVE Vulnerabilities

45,295 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-46331CRITICAL9.8OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z...
CVE-2025-32777HIGH8.2Volcano is a Kubernetes-native batch scheduling system. Prior to versions 1.11.2, 1.10.2, 1.9.1, 1.11.0-network-topology...
CVE-2025-2170HIGH7.2A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface, wh...
CVE-2025-24887MEDIUM6.3OpenCTI is an open-source cyber threat intelligence platform. In versions starting from 6.4.8 to before 6.4.10, the allo...
CVE-2025-4135MEDIUM6.3A vulnerability was found in Netgear WG302v2 up to 5.2.9 and classified as critical. Affected by this issue is the funct...
CVE-2025-46619HIGH7.6A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that ...
CVE-2025-44194HIGH7.3SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?p...
CVE-2025-44193HIGH7.6SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?p...
CVE-2025-44192CRITICAL9.8SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?p...
CVE-2025-3269Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.
CVE-2025-39413HIGH8.8Missing Authorization vulnerability in David Gwyer Simple Sitemap – Create a Responsive HTML Sitemap simple-sitemap.This...
CVE-2025-33074HIGH8.8Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute c...
CVE-2025-30392CRITICAL9.8Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-30391HIGH7.5Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network.
CVE-2025-30390HIGH8.8Improper authorization in Azure allows an authorized attacker to elevate privileges over a network.
CVE-2025-30389CRITICAL9.8Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-2156Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.
CVE-2025-24091MEDIUM5.5An app could impersonate system notifications. Sensitive notifications now require restricted entitlements. This issue i...
CVE-2025-21416HIGH8.8Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network.
CVE-2025-3859MEDIUM6.1Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating be...
CVE-2025-3599HIGH7.5Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevat...
CVE-2025-4122HIGH8.8A vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been rated as critical. Affected by this issue is the f...
CVE-2025-46342HIGH8.2Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.13.5 and 1.14.0, it...
CVE-2025-32974CRITICAL9XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.8 and from 16.0.0-rc-1 to before 1...
CVE-2025-32973CRITICAL9XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.12, from 16.0.0-rc-1 to before 16....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now