2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-62518HIGH8.1astral-tokio-tar is a tar archive reading/writing library for async Rust. Versions of astral-tokio-tar prior to 0.5.6 co...
CVE-2025-60500HIGH7.2QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass...
CVE-2025-61220HIGH7.5The incomplete verification mechanism in the AutoBizLine com.mysecondline.app 1.2.91 allows attackers to log in as other...
CVE-2025-60751HIGH7.5GeographicLib 2.5 is vulnerable to Buffer Overflow in GeoConvert DMS::InternalDecode.
CVE-2025-22166HIGH7.5This High severity DoS (Denial of Service) vulnerability was introduced in version 2.0 of Confluence Data Center. Thi...
CVE-2025-60344HIGH8.6A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attacker...
CVE-2025-9339HIGH7.1SQL injection vulnerability in the fields of warehouse document filtering form in SIMPLE.ERP software allows logged-in u...
CVE-2025-11151HIGH8.2Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Sensitive System Information to an Unauthorized ...
CVE-2025-10020HIGH8.8Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability...
CVE-2025-9428HIGH8.8Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key u...
CVE-2025-10641HIGH7.1All WorkExaminer Professional traffic between monitoring client, console and server is transmitted as plain text. This a...
CVE-2025-10639HIGH8.8The WorkExaminer Professional server installation comes with an FTP server that is used to receive the client logs on TC...
CVE-2025-11949HIGH8.7EasyFlow .NET and EasyFlow AiNet, developed by Digiwin, has a Missing Authentication vulnerability, allowing unauthentic...
CVE-2025-9133HIGH8.1A missing authorization vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series fi...
CVE-2025-8078HIGH7.2A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, US...
CVE-2025-7850HIGH7.2A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.
CVE-2025-6541HIGH8.8An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.
CVE-2025-62658HIGH7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foun...
CVE-2025-61301HIGH7.5Denial-of-analysis in reporting/mongodb.py and reporting/jsondump.py in CAPEv2 (commit 52e4b43, on 2025-05-17) allows at...
CVE-2025-8052HIGH8.8SQL Injection vulnerability in opentext Flipper allows SQL Injection.  The vulnerability could allow a low privilege us...
CVE-2025-8049HIGH8.8Insufficient Granularity of Access Control vulnerability in opentext Flipper allows Exploiting Incorrectly Configured Ac...
CVE-2025-62697HIGH8.8Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in The ...
CVE-2025-62527HIGH7.1Taguette is an open source qualitative research tool. An issue has been discovered in Taguette versions prior to 1.5.0. ...
CVE-2025-61488HIGH7.6An issue in Senayan Library Management System (SLiMS) 9 Bulian v.9.6.1 allows a remote attacker to execute arbitrary cod...
CVE-2025-62510HIGH8.1FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In version 1.4.0...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now