2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-9713HIGH8.8Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve re...
CVE-2025-61688HIGH7.5Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.1.5 and 1.0.2, Omni might leak sensit...
CVE-2025-59836HIGH7.5Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.1.5 and 1.0.2, there is a nil pointer...
CVE-2025-11622HIGH7.8Insecure deserialization in Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to esc...
CVE-2025-62170HIGH7.5rAthena is an open-source cross-platform MMORPG server. A use-after-free vulnerability exists in the RODEX functionality...
CVE-2025-7707HIGH7.8The llama_index library version 0.12.33 sets the NLTK data directory to a subdirectory of the codebase by default, which...
CVE-2025-11695HIGH7.5When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects M...
CVE-2025-43991HIGH7.1SupportAssist for Home PCs versions 4.8.2 and prior and SupportAssist for Business PCs versions 4.5.3 and prior, contain...
CVE-2025-37729HIGH7.2Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a ma...
CVE-2025-9902HIGH7.5Authorization Bypass Through User-Controlled Key vulnerability in AKIN Software Computer Import Export Industry and Trad...
CVE-2025-9968HIGH8.5A link following vulnerability exists in the UnifyScanner component of Armoury Crate. This vulnerability may be triggere...
CVE-2025-11675HIGH8.6Enterprise Cloud Database developed by Ragic has an Arbitrary File Upload vulnerability, allowing privileged remote atta...
CVE-2025-11673HIGH8.6SOOP-CLM developed by PiExtract has a Hidden Functionality vulnerability, allowing privileged remote attackers to exploi...
CVE-2025-11668HIGH7.2A vulnerability was determined in code-projects Automated Voting System 1.0. Affected by this issue is some unknown func...
CVE-2025-11667HIGH8.8A vulnerability was found in code-projects Automated Voting System 1.0. Affected by this vulnerability is an unknown fun...
CVE-2025-8915HIGH8.7Hardcoded TLS private key and certificate in firmware in Kiloview N30 2.02.246 allows malicious adversary to do a Mann-i...
CVE-2025-11666HIGH7A flaw has been found in Tenda RP3 Pro up to 22.5.7.93. This impacts an unknown function of the file force_upgrade.sh of...
CVE-2025-0636HIGH8.4EMCLI contains a high severity vulnerability where improper neutralization of special elements used in an OS command cou...
CVE-2025-31996HIGH7.5HCL Unica Platform is affected by unprotected files due to improper access controls.  These files may contain sensitive...
CVE-2025-11654HIGH7.3A vulnerability was identified in yousaf530 Inferno Online Clothing Store up to 827dd42bfbe380e8de76fdc67958c24cf1246208...
CVE-2025-11653HIGH8.8A vulnerability was determined in UTT HiPER 2620G up to 3.1.4. Impacted is the function strcpy of the file /goform/fNTP....
CVE-2025-11652HIGH8.8A vulnerability was found in UTT 进取 518G up to V3v3.2.7-210919-161313. This issue affects some unknown processing of the...
CVE-2025-11651HIGH8.8A vulnerability has been found in UTT 进取 518G up to V3v3.2.7-210919-161313. This vulnerability affects the function sub_...
CVE-2025-11648HIGH7.4A vulnerability has been found in Tomofun Furbo 360 and Furbo Mini. Impacted is an unknown function of the file TF_FQDN....
CVE-2025-11646HIGH8.1A vulnerability was detected in Tomofun Furbo 360 and Furbo Mini. This vulnerability affects unknown code of the compone...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now