2025 CVE Vulnerabilities

45,295 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-3857HIGH8.7When reading binary Ion data through Amazon.IonDotnet using the RawBinaryReader class, Amazon.IonDotnet does not check t...
CVE-2025-32793MEDIUM4Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.15.0 to 1.15.15, 1...
CVE-2025-32431CRITICAL9.1Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. In versions prior to 2.11.24, 3.3.6, and 3.4.0-...
CVE-2025-28367MEDIUM6.5mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. A...
CVE-2025-2517LOW2.3Reference to Expired Domain Vulnerability in OpenText™ ArcSight Enterprise Security Manager.
CVE-2025-2298HIGH8.4An improper authorization vulnerability in Dremio Software allows authenticated users to delete arbitrary files that the...
CVE-2025-29660CRITICAL9.8A vulnerability exists in the daemon process of the Yi IOT XY-3820 v6.0.24.10, which exposes a TCP service on port 6789....
CVE-2025-29659CRITICAL9.8Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmd_listen" function located in the "cmd" bi...
CVE-2025-29287CRITICAL9.8An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary cod...
CVE-2025-28121MEDIUM6.1code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" p...
CVE-2025-43916LOW3.4Sonos api.sonos.com through 2025-04-21, when the /login/v3/oauth endpoint is used, accepts a redirect_uri containing use...
CVE-2025-32408LOW2.5In Soffid Console 3.6.31 before 3.6.32, authorization to use the pam service is mishandled.
CVE-2025-3840LOW2.1An improper neutralization of input vulnerability was identified in the End of Life (EOL) OVA based connect installer co...
CVE-2025-3838MEDIUM6.1An Improper Authorization vulnerability was identified in the EOL OVA based connect component which is deployed for inst...
CVE-2025-3837MEDIUM6.1An improper input validation vulnerability is identified in the End of Life (EOL) OVA based connect component which is d...
CVE-2025-25228LOW3.8A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execu...
CVE-2025-0632CRITICAL9.2Local File Inclusion (LFI) vulnerability in a Render function of Formulatrix Rock Maker Web (RMW) allows a remote attack...
CVE-2025-43973CRITICAL9.8An issue was discovered in GoBGP before 3.35.0. pkg/packet/rtr/rtr.go does not verify that the input length corresponds ...
CVE-2025-43972HIGH7.5An issue was discovered in GoBGP before 3.35.0. An attacker can cause a crash in the pkg/packet/bgp/bgp.go flowspec pars...
CVE-2025-43971HIGH7.5An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value...
CVE-2025-43970MEDIUM5.3An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g., by...
CVE-2025-43967HIGH7.5libheif before 1.19.6 has a NULL pointer dereference in ImageItem_Grid::get_decoder in image-items/grid.cc because a gri...
CVE-2025-43966HIGH7.5libheif before 1.19.6 has a NULL pointer dereference in ImageItem_iden in image-items/iden.cc.
CVE-2025-43964CRITICAL9.8In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum...
CVE-2025-43963CRITICAL9.1In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp allows out-of-buffer access because split_col an...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now