2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-11493HIGH7.5The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updat...
CVE-2025-11492HIGH7.5In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on...
CVE-2025-62409HIGH7.5Envoy is a cloud-native, open source edge and service proxy. Prior to 1.36.1, 1.35.5, 1.34.9, and 1.33.10, large request...
CVE-2025-34519HIGH7.5Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an insecure hashing algorithm vulnerability. The product ...
CVE-2025-34518HIGH7.5Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a relative path traversal vulnerability in get_file_conte...
CVE-2025-34517HIGH7.5Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an absolute path traversal vulnerability in get_file_cont...
CVE-2025-34514HIGH8.8Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection vulnerabilities in mul...
CVE-2025-36128HIGH7.5IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of th...
CVE-2025-62496HIGH8.8A vulnerability exists in the QuickJS engine's BigInt string parsing logic (js_bigint_from_string) when attempting to cr...
CVE-2025-62495HIGH8.8An integer overflow vulnerability exists in the QuickJS regular expression engine (libregexp) due to an inconsistent rep...
CVE-2025-62494HIGH8.8A type confusion vulnerability exists in the handling of the string addition (+) operation within the QuickJS engine. ...
CVE-2025-62491HIGH8.8A Use-After-Free (UAF) vulnerability exists in the QuickJS engine's standard library when iterating over the global list...
CVE-2025-62490HIGH8.8In quickjs, in js_print_object, when printing an array, the function first fetches the array length and then loops over ...
CVE-2025-61543HIGH7.1A Host Header Injection vulnerability exists in the password reset functionality of CraftMyCMS 4.0.2.2. The system uses ...
CVE-2025-61541HIGH7.1Webmin 2.510 is vulnerable to a Host Header Injection in the password reset functionality (forgot_send.cgi). The reset l...
CVE-2025-61536HIGH8.2FelixRiddle dev-jobs-handlebars 1.0 uses absolute password-reset (magic) links using the untrusted `req.headers.host` he...
CVE-2025-41253HIGH7.5The following versions of Spring Cloud Gateway Server Webflux may be vulnerable to the ability to expose environment var...
CVE-2025-22381HIGH8.2Aggie 2.6.1 has a Host Header injection vulnerability in the forgot password functionality, allowing an attacker to rese...
CVE-2025-54658HIGH7.8An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For...
CVE-2025-53951HIGH7.8An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For...
CVE-2025-61581HIGH7.5** UNSUPPORTED WHEN ASSIGNED ** Inefficient Regular Expression Complexity vulnerability in Apache Traffic Control. This...
CVE-2025-58075HIGH8.1Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to jo...
CVE-2025-58073HIGH8.1Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to jo...
CVE-2025-41020HIGH7.5Insecure direct object reference (IDOR) vulnerability in Sergestec's Exito v8.0. This vulnerability allows an attacker t...
CVE-2025-62585HIGH7.5Whale browser before 4.33.325.17 allows an attacker to bypass the Content Security Policy via a specific scheme in a dua...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now