2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-68705CRITICAL9.8RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.78, RustFS contai...
CVE-2025-66620HIGH7.2An unused webshell in MicroServer allows unlimited login attempts, with sudo rights on certain files and directories. An...
CVE-2025-64305MEDIUM6.5MicroServer copies parts of the system firmware to an unencrypted external SD card on boot, which contains user and vend...
CVE-2025-61939MEDIUM4.4An unused function in MicroServer can start a reverse SSH connection to a vendor registered domain, without mutual authe...
CVE-2025-66560HIGH7.5Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. Prior to versions 3.31.0, 3....
CVE-2025-61782MEDIUM6.1OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6....
CVE-2025-61492CRITICAL10A command injection vulnerability in the execute_command function of terminal-controller-mcp 0.1.7 allows attackers to e...
CVE-2025-58441MEDIUM6.5Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, there is a blind server-si...
CVE-2025-4677HIGH7.1Insufficient Session Expiration vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.Thi...
CVE-2025-67366HIGH7.5@sylphxltd/filesystem-mcp v0.5.8 is an MCP server that provides file content reading functionality. Version 0.5.8 of fil...
CVE-2025-67364HIGH7.5fast-filesystem-mcp version 3.4.0 contains a critical path traversal vulnerability in its file operation tools including...
CVE-2025-66837MEDIUM6.8A file upload vulnerability in ARIS 10.0.23.0.3587512 allows attackers to execute arbitrary code via uploading a crafted...
CVE-2025-66786HIGH7.5OpenAirInterface CN5G AMF<=v2.0.1 There is a logical error when processing JSON format requests. Unauthorized remote att...
CVE-2025-66686MEDIUM6.1A stored Cross-Site Scripting (XSS) vulnerability exists in Perch CMS version 3.2. An authenticated attacker with admini...
CVE-2025-65805HIGH7.5OpenAirInterface CN5G AMF<=v2.1.9 has a buffer overflow vulnerability in processing NAS messages. Unauthorized remote at...
CVE-2025-61489MEDIUM6.5A command injection vulnerability in the shell_exec function of sonirico mcp-shell v0.3.1 allows attackers to execute ar...
CVE-2025-4676HIGH8.8Incorrect Implementation of Authentication Algorithm vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP C...
CVE-2025-4675HIGH7.1Improper Check for Unusual or Exceptional Conditions vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP C...
CVE-2025-12543CRITICAL9.6A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The...
CVE-2025-66838MEDIUM6.5In Aris v10.0.23.0.3587512 and before, the file upload functionality does not enforce any rate limiting or throttling, a...
CVE-2025-62327MEDIUM4.9In HCL DevOps Deploy 8.1.2.0 through 8.1.2.3, a user with LLM configuration privileges may be able to recover a credenti...
CVE-2025-49335MEDIUM4.9Server-Side Request Forgery (SSRF) vulnerability in minnur External Media external-media allows Server Side Request Forg...
CVE-2025-6225MEDIUM6.9Kieback&Peter Neutrino-GLT product is used for building management. It's web component "SM70 PHWEB" is vulnerable to she...
CVE-2025-15479MEDIUM5.4Stored cross-site scripting (XSS, CWE-79) in the survey content and administration functionality in Data Illusion Zumbru...
CVE-2025-47552CRITICAL9.8Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This is...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now