2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-62495HIGH8.8An integer overflow vulnerability exists in the QuickJS regular expression engine (libregexp) due to an inconsistent rep...
CVE-2025-62494HIGH8.8A type confusion vulnerability exists in the handling of the string addition (+) operation within the QuickJS engine. ...
CVE-2025-62491HIGH8.8A Use-After-Free (UAF) vulnerability exists in the QuickJS engine's standard library when iterating over the global list...
CVE-2025-62490HIGH8.8In quickjs, in js_print_object, when printing an array, the function first fetches the array length and then loops over ...
CVE-2025-61543HIGH7.1A Host Header Injection vulnerability exists in the password reset functionality of CraftMyCMS 4.0.2.2. The system uses ...
CVE-2025-61541HIGH7.1Webmin 2.510 is vulnerable to a Host Header Injection in the password reset functionality (forgot_send.cgi). The reset l...
CVE-2025-61536HIGH8.2FelixRiddle dev-jobs-handlebars 1.0 uses absolute password-reset (magic) links using the untrusted `req.headers.host` he...
CVE-2025-41253HIGH7.5The following versions of Spring Cloud Gateway Server Webflux may be vulnerable to the ability to expose environment var...
CVE-2025-22381HIGH8.2Aggie 2.6.1 has a Host Header injection vulnerability in the forgot password functionality, allowing an attacker to rese...
CVE-2025-54658HIGH7.8An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For...
CVE-2025-53951HIGH7.8An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For...
CVE-2025-61581HIGH7.5** UNSUPPORTED WHEN ASSIGNED ** Inefficient Regular Expression Complexity vulnerability in Apache Traffic Control. This...
CVE-2025-58075HIGH8.1Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to jo...
CVE-2025-58073HIGH8.1Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to jo...
CVE-2025-41020HIGH7.5Insecure direct object reference (IDOR) vulnerability in Sergestec's Exito v8.0. This vulnerability allows an attacker t...
CVE-2025-62585HIGH7.5Whale browser before 4.33.325.17 allows an attacker to bypass the Content Security Policy via a specific scheme in a dua...
CVE-2025-62584HIGH7.5Whale browser before 4.33.325.17 allows an attacker to bypass the Same-Origin Policy in a dual-tab environment.
CVE-2025-10706HIGH8.8The Classified Pro theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability che...
CVE-2025-58778HIGH8.6Multiple versions of RG-EST300 provided by Ruijie Networks provide SSH server functionality. It is not documented in the...
CVE-2025-62580HIGH7.8ASDA-Soft Stack-based Buffer Overflow Vulnerability
CVE-2025-62579HIGH7.8ASDA-Soft Stack-based Buffer Overflow Vulnerability
CVE-2025-43281HIGH7.8The issue was addressed with improved authentication. This issue is fixed in macOS Sequoia 15.6. A local attacker may be...
CVE-2025-11619HIGH8.8Improper certificate validation when connecting to gateways in Devolutions Server 2025.3.2 and earlier allows attackers ...
CVE-2025-62382HIGH7.7Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.2, Frigate'...
CVE-2025-62381HIGH8.3sveltekit-superforms makes SvelteKit forms a pleasure to use. sveltekit-superforms v2.27.3 and prior are susceptible to ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now