2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-54550HIGH8.1The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value from xco...
CVE-2025-61848HIGH7.2An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiA...
CVE-2025-53847HIGH8.8A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 thro...
CVE-2025-7389HIGH8.2A vulnerability in the AdminServer component of OpenEdge on all supported platforms grants its authenticated users OS-le...
CVE-2025-51414HIGH8.8In Phpgurukul Online Course Registration v3.1, an arbitrary file upload vulnerability was discovered within the profile ...
CVE-2025-3756HIGH7.1A vulnerability exists in the command handling of the IEC 61850 communication stack included in the product revisions li...
CVE-2025-69627HIGH8.4Nitro PDF Pro for Windows 14.41.1.4 contains a heap use-after-free vulnerability in the implementation of the JavaScript...
CVE-2025-69624HIGH7.5Nitro PDF Pro before 14.43 for Windows contains a NULL pointer dereference vulnerability in the JavaScript implementatio...
CVE-2025-66769HIGH7.5A NULL pointer dereference in Nitro PDF Pro for Windows v14.41.1.4 allows attackers to cause a Denial of Service (DoS) v...
CVE-2025-66236HIGH7.5Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate ...
CVE-2025-5804HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-58920HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zootemplate Cerato...
CVE-2025-58913HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-59969HIGH7.1A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the advanced forwarding toolki...
CVE-2025-13914HIGH8.1A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a...
CVE-2025-70364HIGH8.8An issue was discovered in Kiamo before 8.4 allowing authenticated administrative attackers to execute arbitrary PHP cod...
CVE-2025-14551HIGH8.1In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation fai...
CVE-2025-70810HIGH8.8Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via t...
CVE-2025-62188HIGH7.5An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler. This vul...
CVE-2025-12664HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 18.8.9, 18.9 before 18.9.5, and 1...
CVE-2025-50673HIGH7.5A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the http_lanport paramet...
CVE-2025-50672HIGH7.5A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /yyxz_...
CVE-2025-50671HIGH7.5A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_...
CVE-2025-50670HIGH7.5A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_...
CVE-2025-50669HIGH7.5A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 and DI-8003G 19.12.10A1 due to improper handling of ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now