2025 CVE Vulnerabilities

45,295 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-32964MEDIUM4.6ManageWiki is a MediaWiki extension allowing users to manage wikis. Prior to commit 00bebea, when enabling a conflicting...
CVE-2025-32963MEDIUM6.9MinIO Operator STS is a native IAM Authentication for Kubernetes. Prior to version 7.1.0, if no audiences are provided f...
CVE-2025-32961MEDIUM6.4The Cuba JPA web API enables loading and saving any entities defined in the application data model by sending simple HTT...
CVE-2025-32960MEDIUM6.4The CUBA REST API add-on performs operations on data and entities. Prior to version 7.2.7, the input parameter, which co...
CVE-2025-32959MEDIUM6.5CUBA Platform is a high level framework for enterprise applications development. Prior to version 7.2.23, the local file...
CVE-2025-32952MEDIUM6.5Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to ...
CVE-2025-32951MEDIUM5.4Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to ...
CVE-2025-32950MEDIUM6.5Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to ...
CVE-2025-32788MEDIUM4.3OctoPrint provides a web interface for controlling consumer 3D printers. In versions up to and including 1.10.3, OctoPri...
CVE-2025-28039CRITICAL9.8TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the s...
CVE-2025-28038CRITICAL9.8TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the s...
CVE-2025-28036CRITICAL9.8TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the se...
CVE-2025-28035CRITICAL9.8TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the set...
CVE-2025-28029HIGH7.3TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2c...
CVE-2025-28027HIGH7.3TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2c...
CVE-2025-28026HIGH7.3TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2c...
CVE-2025-34028CRITICAL10The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent insta...
CVE-2025-29339HIGH7.5An issue in UPF in Open5GS UPF versions up to v2.7.2 results an assertion failure vulnerability in PFCP session paramete...
CVE-2025-27907LOW2.7IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to server-side request forgery (SSRF). This may allow an auth...
CVE-2025-3767HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon BAM (Bool...
CVE-2025-28037CRITICAL9.8TOTOLINK A810R V4.1.2cu.5182_B20201026 and A950RG V4.1.2cu.5161_B20200903 were found to contain a pre-auth remote comman...
CVE-2025-28031MEDIUM6.5TOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a hardcoded password for the telnet service in product....
CVE-2025-28030HIGH8.8TOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a stack overflow via the startTime and endTime paramete...
CVE-2025-28024CRITICAL9.8TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the cstecgi.cgi
CVE-2025-23251CRITICAL9.8NVIDIA NeMo Framework contains a vulnerability where a user could cause an improper control of generation of code by rem...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now