2025 CVE Vulnerabilities

45,323 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-59473HIGH7.2SQL Injection vulnerability in the Structure for Admin authenticated user
CVE-2025-59472HIGH7.5A denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in min...
CVE-2025-59471HIGH7.5A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for t...
CVE-2025-9820MEDIUM4A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 tok...
CVE-2025-9615LOW3.3A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. Ne...
CVE-2025-9522MEDIUM5.3Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests t...
CVE-2025-9521MEDIUM6.5Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypa...
CVE-2025-9520MEDIUM6.8An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate r...
CVE-2025-14969MEDIUM4.3A flaw was found in Hibernate Reactive. When an HTTP endpoint is exposed to perform database operations, a remote client...
CVE-2025-14525MEDIUM6.4A flaw was found in kubevirt. A user within a virtual machine (VM), if the guest agent is active, can exploit this by ca...
CVE-2025-14459HIGH8.5A flaw was found in KubeVirt Containerized Data Importer (CDI). This vulnerability allows a user to clone PersistentVolu...
CVE-2025-11687MEDIUM6.1A flaw was found in the gi-docgen. This vulnerability allows arbitrary JavaScript execution in the context of the page —...
CVE-2025-11065MEDIUM5.3A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode...
CVE-2025-70368MEDIUM5.4Worklenz version 2.1.5 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Project Updates feature. An att...
CVE-2025-14756HIGH8.8Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing...
CVE-2025-71178HIGH7.1Crucial Storage Executive installer versions prior to 11.08.082025.00 contain a DLL preloading vulnerability. During ins...
CVE-2025-57785MEDIUM6.5A Double Free in XSLT `show_index` has been identified in Hiawatha webserver version 11.7 which allows an unauthenticate...
CVE-2025-57784LOW3.3Tomahawk auth timing attack due to usage of `strcmp` has been identified in Hiawatha webserver version 11.7 which allows...
CVE-2025-57783MEDIUM5.3Improper header parsing may lead to request smuggling has been identified in Hiawatha webserver version 11.7 which allow...
CVE-2025-70982CRITICAL9.9Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to ...
CVE-2025-67274HIGH7.5An issue in continuous.software aangine v.2025.2 allows a remote attacker to obtain sensitive information via the excel-...
CVE-2025-50537MEDIUM5.5Stack overflow vulnerability in eslint before 9.26.0 when serializing objects with circular references in eslint/lib/sha...
CVE-2025-59109MEDIUM5.1The dormakaba registration units 9002 (PIN Pad Units) have an exposed UART header on the backside. The PIN pad is sendin...
CVE-2025-59108CRITICAL9.2By default, the password for the Access Manager's web interface, is set to 'admin'. In the tested version changing the p...
CVE-2025-59107HIGH8.5Dormakaba provides the software FWServiceTool to update the firmware version of the Access Managers via the network. The...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now