2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-37735HIGH7Improper preservation of permissions in Elastic Defend on Windows hosts can lead to arbitrary files on the system being ...
CVE-2025-11956HIGH8.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Soft...
CVE-2025-9338HIGH7.3A improper restriction of operations within the bounds of a memory buffer exists in AsIO3.sys driver. This vulnerability...
CVE-2025-64171HIGH8.7MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versions 0.13.3 and below, there is a cross-n...
CVE-2025-55278HIGH8.1Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accep...
CVE-2025-12779HIGH8.8Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8,...
CVE-2025-63417HIGH7.2A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the SelfBest platform 2023.3 allows authe...
CVE-2025-12745HIGH7.8A weakness has been identified in QuickJS up to eb2c89087def1829ed99630cb14b549d7a98408c. This affects the function js_a...
CVE-2025-11093HIGH7.2An arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restrictions in the Graal...
CVE-2025-10907HIGH7.2An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded conte...
CVE-2025-63248HIGH7.5DWSurvey 6.14.0 is vulnerable to Incorrect Access Control. When deleting a questionnaire, replacing the questionnaire ID...
CVE-2025-46364HIGH7.2Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user with known password can run CLI...
CVE-2025-45379HIGH8.4Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run comma...
CVE-2025-43990HIGH7.8Dell Command Monitor (DCM), versions prior to 10.12.3.28, contains an Execution with Unnecessary Privileges vulnerabilit...
CVE-2025-30479HIGH7.2Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run comma...
CVE-2025-20376HIGH7.2A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute a...
CVE-2025-20375HIGH7.2A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute a...
CVE-2025-20343HIGH7.5A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures on Cisco Identity Servi...
CVE-2025-57130HIGH8.8An Incorrect Access Control vulnerability in the user management component of ZwiiCMS up to v13.6.07 allows a remote, au...
CVE-2025-64458HIGH7.5An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. NFKC normalization in Python is s...
CVE-2025-61084HIGH7.1MDaemon Mail Server 23.5.2 validates SPF, DKIM, and DMARC using the email enclosed in angle brackets (<>) in the From: h...
CVE-2025-46784HIGH7.5A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr&#39;ouver...
CVE-2025-46705HIGH7.5A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr&#39;ouvert Lasso 2.5.1 and 2....
CVE-2025-46404HIGH7.5A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr&#39;ouvert La...
CVE-2025-3125HIGH7.2An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAp...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now