2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-66560HIGH7.5Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. Prior to versions 3.31.0, 3....
CVE-2025-61782MEDIUM6.1OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6....
CVE-2025-61492CRITICAL10A command injection vulnerability in the execute_command function of terminal-controller-mcp 0.1.7 allows attackers to e...
CVE-2025-58441MEDIUM6.5Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, there is a blind server-si...
CVE-2025-4677HIGH7.1Insufficient Session Expiration vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.Thi...
CVE-2025-67366HIGH7.5@sylphxltd/filesystem-mcp v0.5.8 is an MCP server that provides file content reading functionality. Version 0.5.8 of fil...
CVE-2025-67364HIGH7.5fast-filesystem-mcp version 3.4.0 contains a critical path traversal vulnerability in its file operation tools including...
CVE-2025-66837MEDIUM6.8A file upload vulnerability in ARIS 10.0.23.0.3587512 allows attackers to execute arbitrary code via uploading a crafted...
CVE-2025-66786HIGH7.5OpenAirInterface CN5G AMF<=v2.0.1 There is a logical error when processing JSON format requests. Unauthorized remote att...
CVE-2025-66686MEDIUM6.1A stored Cross-Site Scripting (XSS) vulnerability exists in Perch CMS version 3.2. An authenticated attacker with admini...
CVE-2025-65805HIGH7.5OpenAirInterface CN5G AMF<=v2.1.9 has a buffer overflow vulnerability in processing NAS messages. Unauthorized remote at...
CVE-2025-61489MEDIUM6.5A command injection vulnerability in the shell_exec function of sonirico mcp-shell v0.3.1 allows attackers to execute ar...
CVE-2025-4676HIGH8.8Incorrect Implementation of Authentication Algorithm vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP C...
CVE-2025-4675HIGH7.1Improper Check for Unusual or Exceptional Conditions vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP C...
CVE-2025-12543CRITICAL9.6A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The...
CVE-2025-66838MEDIUM6.5In Aris v10.0.23.0.3587512 and before, the file upload functionality does not enforce any rate limiting or throttling, a...
CVE-2025-62327MEDIUM4.9In HCL DevOps Deploy 8.1.2.0 through 8.1.2.3, a user with LLM configuration privileges may be able to recover a credenti...
CVE-2025-49335MEDIUM4.9Server-Side Request Forgery (SSRF) vulnerability in minnur External Media external-media allows Server Side Request Forg...
CVE-2025-6225MEDIUM6.9Kieback&Peter Neutrino-GLT product is used for building management. It's web component "SM70 PHWEB" is vulnerable to she...
CVE-2025-15479MEDIUM5.4Stored cross-site scripting (XSS, CWE-79) in the survey content and administration functionality in Data Illusion Zumbru...
CVE-2025-47552CRITICAL9.8Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This is...
CVE-2025-46494HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesgrove Widget...
CVE-2025-46434MEDIUM6.5Missing Authorization vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro theplus_elementor_addon all...
CVE-2025-46256MEDIUM6.4Path Traversal: '.../...//' vulnerability in SigmaPlugin Advanced Database Cleaner PRO allows Path Traversal.This issue ...
CVE-2025-32303CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla WPCHURCH ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now