2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-52663HIGH7.3A vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintention...
CVE-2025-48984HIGH8.8A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
CVE-2025-48982HIGH7.8This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator ...
CVE-2025-34298HIGH8.8Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change ...
CVE-2025-34287HIGH7.8Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodical...
CVE-2025-34286HIGH7.2Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run C...
CVE-2025-34284HIGH8.8Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. Insufficient validatio...
CVE-2025-34280HIGH7.2Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management function...
CVE-2025-34134HIGH7.2Nagios XI versions prior to 2024R1.4.2 contain a remote code execution vulnerability in the Business Process Intelligenc...
CVE-2025-8850HIGH8.8In danny-avila/librechat version 0.7.9, there is an insecure API design issue in the 2-Factor Authentication (2FA) flow....
CVE-2025-63423HIGH7.5Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 was discovered to store the Administrator passw...
CVE-2025-61498HIGH7.5A buffer overflow in the UPnP service of Tenda AC8 Hardware v03.03.10.01 allows attackers to cause a Denial of Service (...
CVE-2025-61141HIGH7.5sqls-server/sqls 0.2.28 is vulnerable to command injection in the config command because the openEditor function passes ...
CVE-2025-3355HIGH7.5IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on t...
CVE-2025-63422HIGH7.5Incorrect access control in the Web management interface in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRou...
CVE-2025-63298HIGH8.2A path traversal vulnerability was identified in SourceCodester Pet Grooming Management System 1.0, affecting the admin/...
CVE-2025-36137HIGH7.2IBM Sterling Connect Direct for Unix 6.2.0.7 through 6.2.0.9 iFix004, 6.4.0.0 through 6.4.0.2 iFix001, and 6.3.0.2 throu...
CVE-2025-64112HIGH8Statmatic is a Laravel and Git powered content management system (CMS). Stored XSS vulnerabilities in Collections and Ta...
CVE-2025-64096HIGH8.8CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL...
CVE-2025-62795HIGH7.1JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.21-lts ...
CVE-2025-62726HIGH8.8n8n is an open source workflow automation platform. Prior to 1.113.0, a remote code execution vulnerability exists in th...
CVE-2025-61196HIGH8.8An issue in BusinessNext CRMnext v.10.8.3.0 allows a remote attacker to execute arbitrary code via the comments input pa...
CVE-2025-61121HIGH7.5Mobile Scanner Android App version 2.12.38 (package name com.glority.everlens), developed by Glority Global Group Ltd., ...
CVE-2025-61120HIGH7.5AG Life Logger Android App version v1.0.2.72 and before (package name com.donki.healthy), developed by IO FIT, K.K., con...
CVE-2025-61119HIGH7.5Kanova Android App version 1.0.27 (package name com.karelane), developed by Karely L.L.C., contains improper access cont...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now