2025 CVE Vulnerabilities

45,295 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-1732MEDIUM6.7An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware vers...
CVE-2025-1731HIGH7.8An incorrect permission assignment vulnerability in the PostgreSQL commands of the Zyxel USG FLEX H series uOS firmware ...
CVE-2025-3856CRITICAL9.8A vulnerability was found in xxyopen Novel-Plus 5.1.0. It has been classified as critical. This affects the function sea...
CVE-2025-3855MEDIUM5.3A vulnerability was found in CodeCanyon RISE Ultimate Project Manager 3.8.2 and classified as problematic. Affected by t...
CVE-2025-3854HIGH8.6A vulnerability, which was classified as critical, was found in H3C GR-3000AX up to V100R006. Affected is the function E...
CVE-2025-3850LOW2.7A vulnerability, which was classified as problematic, has been found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This issu...
CVE-2025-3849MEDIUM6.5A vulnerability classified as problematic was found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This vulnerability affects...
CVE-2025-2987MEDIUM5.4IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated...
CVE-2025-3847CRITICAL9.8A vulnerability classified as critical has been found in markparticle WebServer up to 1.0. This affects an unknown part ...
CVE-2025-3846CRITICAL9.8A vulnerability was found in markparticle WebServer up to 1.0. It has been rated as critical. Affected by this issue is ...
CVE-2025-3845CRITICAL9.8A vulnerability was found in markparticle WebServer up to 1.0. It has been declared as critical. Affected by this vulner...
CVE-2025-3843MEDIUM6.5A vulnerability was found in panhainan DS-Java 1.0. It has been classified as problematic. Affected is an unknown functi...
CVE-2025-3842CRITICAL9.8A vulnerability was found in panhainan DS-Java 1.0 and classified as critical. This issue affects the function uploadUse...
CVE-2025-32958CRITICAL9.8Adept is a language for general purpose programming. Prior to commit a1a41b7, the remoteBuild.yml workflow file uses act...
CVE-2025-32956HIGH8ManageWiki is a MediaWiki extension allowing users to manage wikis. Versions before commit f504ed8, are vulnerable to SQ...
CVE-2025-32955MEDIUM6Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Versions from 0.12.0 to befor...
CVE-2025-3841CRITICAL9.8A vulnerability, which was classified as problematic, was found in wix-incubator jam up to e87a6fd85cf8fb5ff37b62b2d68f9...
CVE-2025-28104CRITICAL9.1Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input.
CVE-2025-28103MEDIUM6.4Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request.
CVE-2025-27086HIGH8.1A vulnerability in the HPE Performance Cluster Manager (HPCM) GUI could allow an attacker to bypass authentication.
CVE-2025-29446Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2025-28102MEDIUM6.1A cross-site scripting (XSS) vulnerability in flaskBlog v2.6.1 allows attackers to execute arbitrary web scripts or HTML...
CVE-2025-28099MEDIUM4.3opencms V2.3 is vulnerable to Arbitrary file read in src/main/webapp/view/admin/document/dataPage.jsp,
CVE-2025-23174HIGH7.5CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVE-2025-43922HIGH8.1The FileWave Windows client before 16.0.0, in some non-default configurations, allows an unprivileged local user to esca...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now