2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-66031HIGH7.5Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled R...
CVE-2025-64344HIGH7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-64335HIGH7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-64334HIGH7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-64333HIGH7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-64332HIGH7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-64331HIGH7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-64330HIGH7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-65202HIGH8TRENDnet TEW-657BRM 1.00.1 has an authenticated remote OS command injection vulnerability in the setup.cgi binary, explo...
CVE-2025-65278HIGH7.5An issue was discovered in file users.json in GroceryMart commit 21934e6 (2020-10-23) allowing unauthenticated attackers...
CVE-2025-12571HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.4.5, 18.5 before 18.5.3, and ...
CVE-2025-66028HIGH8.2OneUptime is a solution for monitoring and managing online services. Prior to version 8.0.5567, OneUptime is vulnerable ...
CVE-2025-65966HIGH8.1OneUptime is a solution for monitoring and managing online services. In version 9.0.5598, a low-permission user can crea...
CVE-2025-65672HIGH7.5Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows unauthorized share and invite access to course sett...
CVE-2025-64129HIGH7.6Zenitel TCIV-3+ is vulnerable to an out-of-bounds write vulnerability, which could allow a remote attacker to crash the...
CVE-2025-55471HIGH7.5Incorrect access control in the getUserFormData function of youlai-boot v2.21.1 allows attackers to access sensitive inf...
CVE-2025-2486HIGH8.8The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, p...
CVE-2025-13084HIGH7.6The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys. ...
CVE-2025-11461HIGH8.8Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user-controlled parameters int...
CVE-2025-46175HIGH7.5Ruoyi v4.8.0 is vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the au...
CVE-2025-56396HIGH8.8An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department havi...
CVE-2025-46174HIGH7.5Ruoyi v4.8.0 vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the reset...
CVE-2025-45311HIGH8.8Insecure permissions in fail2ban-client v0.11.2 allows attackers with limited sudo privileges to perform arbitrary opera...
CVE-2025-13601HIGH7.7A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_u...
CVE-2025-13735HIGH7.4Out-of-bounds Read vulnerability in ASR1903、ASR3901 in ASR Lapwing_Linux on Linux (nr_fw modules). This vulnerability is...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now