2025 CVE Vulnerabilities

45,295 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-46221Rejected reason: Not used
CVE-2025-46220Rejected reason: Not used
CVE-2025-46219Rejected reason: Not used
CVE-2025-46218Rejected reason: Not used
CVE-2025-46217Rejected reason: Not used
CVE-2025-46216Rejected reason: Not used
CVE-2025-1021HIGH7.5Missing authorization vulnerability in synocopy in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-...
CVE-2025-3441Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-37088MEDIUM6.8A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on race conditions...
CVE-2025-27087MEDIUM5.5A vulnerability in the kernel of the Cray Operating System (COS) could allow an attacker to perform a local Denial of Se...
CVE-2025-37087CRITICAL9.8A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access...
CVE-2025-32965CRITICAL9.3xrpl.js is a JavaScript/TypeScript API for interacting with the XRP Ledger in Node.js and the browser. Versions 4.2.1, 4...
CVE-2025-29743MEDIUM6.5D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting.
CVE-2025-26159MEDIUM6.1Laravel Starter 11.11.0 is vulnerable to Cross Site Scripting (XSS) in the tags feature. Any user with the ability of cr...
CVE-2025-31328MEDIUM4.6SAP Learning Solution is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to trick authenticated us...
CVE-2025-31327MEDIUM4.3SAP Field Logistics Manage Logistics application OData meta-data property is vulnerable to data tampering, due to which ...
CVE-2025-29621HIGH7.3Francois Jacquet RosarioSIS v12.0.0 was discovered to contain a content spoofing vulnerability in the Theme configuratio...
CVE-2025-23253LOW2.5NVIDIA NvContainer service for Windows contains a vulnerability in its usage of OpenSSL, where an attacker could exploit...
CVE-2025-43952MEDIUM6.1A cross-site scripting (reflected XSS) vulnerability was found in Mettler Toledo FreeWeight.Net Web Reports Viewer 8.4.0...
CVE-2025-43951CRITICAL9.8LabVantage before LV 8.8.0.13 HF6 allows local file inclusion. Authenticated users can retrieve arbitrary files from the...
CVE-2025-43950HIGH7.8DPMAdirektPro 4.1.5 is vulnerable to DLL Hijacking. It happens by placing a malicious DLL in a directory (in the absence...
CVE-2025-43949CRITICAL9.8MuM (aka Mensch und Maschine) MapEdit (aka mapedit-web) 24.2.3 is vulnerable to SQL Injection that allows an attacker to...
CVE-2025-43948HIGH7.3Codemers KLIMS 1.6.DEV allows Python code injection. A user can provide Python code as an input value for a parameter or...
CVE-2025-43947HIGH7.3Codemers KLIMS 1.6.DEV lacks a proper access control mechanism, allowing a normal KLIMS user to perform all the actions ...
CVE-2025-43946CRITICAL9.8TCPWave DDI 11.34P1C2 allows Remote Code Execution via Unrestricted File Upload (combined with Path Traversal).

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now