2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-6979HIGH8.8Captive Portal can allow authentication bypass
CVE-2025-6978HIGH7.2Diagnostics command injection vulnerability
CVE-2025-54808HIGH7.8Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 stores authentication tokens in a file locat...
CVE-2025-23352HIGH7.8NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause uninitiali...
CVE-2025-23347HIGH7.8NVIDIA Project G-Assist contains a vulnerability where an attacker might be able to escalate permissions. A successful e...
CVE-2025-11621HIGH8.1Vault and Vault Enterprise’s (“Vault”) AWS Auth method may be susceptible to authentication bypass if the role of the co...
CVE-2025-62713HIGH7.2Kottster is a self hosted Node.js admin panel. From versions 3.2.0 to before 3.3.2, Kottster contains a pre-authenticati...
CVE-2025-62169HIGH8.1OctoPrint-SpoolManager is a plugin for managing spools and all their usage metadata. In versions 1.8.0a2 and older of th...
CVE-2025-59048HIGH8.1OpenBao's AWS Plugin generates AWS access credentials based on IAM policies. Prior to version 0.1.1, the AWS Plugin is v...
CVE-2025-50950HIGH7.5Audiofile v0.3.7 was discovered to contain a NULL pointer dereference via the ModuleState::setup function.
CVE-2025-61136HIGH7.1A Host Header Injection vulnerability in the password reset component in axewater sharewarez v2.4.3 allows remote attack...
CVE-2025-61132HIGH7.1A Host Header Injection vulnerability in the password reset component in levlaz braindump v0.4.14 allows remote attacker...
CVE-2025-62399HIGH7.5Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, makin...
CVE-2025-12105HIGH7.5A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-base...
CVE-2025-10914HIGH7.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Soft...
CVE-2025-61865HIGH8.4Multiple NAS management applications provided by I-O DATA DEVICE, INC. register Windows services with unquoted file path...
CVE-2025-11575HIGH8.8Incorrect Default Permissions vulnerability in MongoDB Atlas SQL ODBC driver on Windows allows Privilege Escalation.This...
CVE-2025-62708HIGH7.5pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability...
CVE-2025-62707HIGH7.5pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability...
CVE-2025-62617HIGH7.2Admidio is an open-source user management solution. Prior to version 4.3.17, an authenticated SQL injection vulnerabilit...
CVE-2025-62614HIGH8.7BookLore is a self-hosted web app for organizing and managing personal book collections. In versions 1.8.1 and prior, an...
CVE-2025-62611HIGH8.2aiomysql is a library for accessing a MySQL database from the asyncio. Prior to version 0.3.0, the client-side settings ...
CVE-2025-62610HIGH8.1Hono is a Web application framework that provides support for any JavaScript runtime. In versions from 1.1.0 to before 4...
CVE-2025-62513HIGH7.5OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log expe...
CVE-2025-60343HIGH7.5Multiple buffer overflows in the AdvSetMacMtuWan function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now