2025 CVE Vulnerabilities

45,296 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-32027MEDIUM6.1Yii is an open source PHP web framework. Prior to 1.1.31, yiisoft/yii is vulnerable to Reflected XSS in specific scenari...
CVE-2025-29150MEDIUM4.3BlueCMS 1.6 suffers from Arbitrary File Deletion via the id parameter in an /publish.php?act=del request.
CVE-2025-0362MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 7.7 before 17.8.7, 17.9 before 17.9.6, and 17.1...
CVE-2025-32743CRITICAL9In ConnMan through 1.44, the lookup string in ns_resolv in dnsproxy.c can be NULL or an empty string when the TC (Trunca...
CVE-2025-32395MEDIUM6Vite is a frontend tooling framework for javascript. Prior to 6.2.6, 6.1.5, 6.0.15, 5.4.18, and 4.5.13, the contents of ...
CVE-2025-32391MEDIUM4.6HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.3, a malicious SVG file ...
CVE-2025-32383HIGH7.2MaxKB (Max Knowledge Base) is an open source knowledge base question-answering system based on a large language model an...
CVE-2025-2469MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.9.6, and 17.10 before 17.10.4. T...
CVE-2025-29088MEDIUM5.5In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial ...
CVE-2025-29017HIGH8.8A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file uplo...
CVE-2025-30148MEDIUM5.4Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. Prior to 5.3.23, bad actor with access to e...
CVE-2025-2408MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions from 13.12 before 17.8.7, 17.9 before 17.9.6, and 17...
CVE-2025-27813HIGH8.1MSI Center before 2.0.52.0 has Missing PE Signature Validation.
CVE-2025-27812HIGH8.1MSI Center before 2.0.52.0 allows TOCTOU Local Privilege Escalation.
CVE-2025-25197MEDIUM5.4Silverstripe Elemental extends a page type to swap the content area for a list of manageable elements to compose a page ...
CVE-2025-1677HIGH7.5A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all up to 17.8.7, 17.9 prior to 17.9.6 and...
CVE-2025-32755CRITICAL9.1In jenkins/ssh-slave Docker images based on Debian, SSH host keys are generated on image creation for images based on De...
CVE-2025-32754CRITICAL9.1In jenkins/ssh-agent Docker images 6.11.1 and earlier, SSH host keys are generated on image creation for images based on...
CVE-2025-1073HIGH7.5Panasonic IR Control Hub (IR Blaster) versions 1.17 and earlier may allow an attacker with physical access to load unaut...
CVE-2025-31411MEDIUM5.9Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in aribhour Linet ERP-Wooco...
CVE-2025-27350HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hugh Mungus Vice V...
CVE-2025-22375CRITICAL9.3An authentication bypass vulnerability was found in Videx's CyberAudit-Web. Through the exploitation of a logic flaw, an...
CVE-2025-22374MEDIUM6A Server-Side Request Forgery (SSRF) vulnerability was discovered in the videx-legacy-ssl web service of Videx’s CyberAu...
CVE-2025-23386HIGH7.8A Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed package gerbera allows the service user gerbera...
CVE-2025-27081MEDIUM6.8A potential security vulnerability in HPE NonStop OSM Service Connection Suite could potentially be exploited to allow a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now