2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-61101HIGH7.5FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_r...
CVE-2025-59151HIGH8.2Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker bloc...
CVE-2025-58356HIGH8.3Constellation is the first Confidential Kubernetes. The Constellation CVM image uses LUKS2-encrypted volumes for persist...
CVE-2025-61100HIGH7.5FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the ospf_opaque_lsa_dum...
CVE-2025-61099HIGH7.5FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the opaque_info_detail ...
CVE-2025-36007HIGH7.8IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to privilege escalation due to imprope...
CVE-2025-55752HIGH7.5Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the r...
CVE-2025-12363HIGH7.5Email Password Disclosure.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
CVE-2025-54968HIGH8.8An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Service does not require authentication. In s...
CVE-2025-27225HIGH7.5TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unau...
CVE-2025-27223HIGH7.5TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints s...
CVE-2025-27222HIGH8.6TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files. However, t...
CVE-2025-12295HIGH8.1A weakness has been identified in D-Link DAP-2695 2.00RC13. The affected element is the function sub_40C6B8 of the compo...
CVE-2025-61247HIGH8.2indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in the password parameter of login.php.
CVE-2025-60425HIGH8.6Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authenticati...
CVE-2025-60424HIGH7.6A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to byp...
CVE-2025-34133HIGH7Wimi Teamwork versions prior to 7.38.17 contains a cross-site request forgery (CSRF) vulnerability in its API. The API a...
CVE-2025-61482HIGH7.2Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local a...
CVE-2025-52268HIGH7.5StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a hardcoded AES key which allows attackers to for...
CVE-2025-52264HIGH8StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a stack overflow via the cgiMain function at down...
CVE-2025-12288HIGH8.8A vulnerability was detected in Bdtask Pharmacy Management System up to 9.4. Affected is an unknown function of the file...
CVE-2025-12287HIGH7.2A security vulnerability has been detected in Bdtask Wholesale Inventory Control and Inventory Management System up to 2...
CVE-2025-9164HIGH8.8Docker Desktop Installer.exe is vulnerable to DLL hijacking due to insecure DLL search order. The installer searches for...
CVE-2025-52263HIGH8An issue in the Web Configuration module of Startcharge Artemis AC Charger 7-22 kW v1.0.4 allows authenticated network-a...
CVE-2025-12286HIGH7.3A weakness has been identified in VeePN up to 1.6.2. This affects an unknown function of the file C:\Program Files (x86)...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now