2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-60375HIGH7.3The authentication mechanism in Perfex CRM before 3.3.1 allows attackers to bypass login credentials due to insufficient...
CVE-2025-59271HIGH8.7Redis Enterprise Elevation of Privilege Vulnerability
CVE-2025-35055HIGH8.8Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrar...
CVE-2025-34248HIGH7.2D-Link Nuclias Connect firmware versions < 1.3.1.4 contain a directory traversal vulnerability within /api/web/dnc/globa...
CVE-2025-11554HIGH8.8A security vulnerability has been detected in Portabilis i-Educar up to 2.9.10. Affected by this issue is some unknown f...
CVE-2025-59146HIGH8.5New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. An authenticate...
CVE-2025-4615HIGH7.2An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® softwar...
CVE-2025-11552HIGH8.8A vulnerability was identified in code-projects Online Complaint Site 1.0. This impacts an unknown function of the file ...
CVE-2025-11573HIGH8.7An infinite loop issue in Amazon.IonDotnet library versions <v1.3.2 may allow a threat actor to cause a denial of servic...
CVE-2025-60004HIGH8.7An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Ne...
CVE-2025-11371HIGH7.5In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local Fil...
CVE-2025-61577HIGH7.5D-Link DIR-816A2_FWv1.10CNB05 was discovered to contain a stack overflow via the statuscheckpppoeuser parameter in the d...
CVE-2025-59976HIGH7.1An arbitrary file download vulnerability in the web interface of Juniper Networks Junos Space allows a network-based aut...
CVE-2025-59975HIGH8.7An Uncontrolled Resource Consumption vulnerability in the HTTP daemon (httpd) of Juniper Networks Junos Space allows an ...
CVE-2025-59968HIGH8.6A Missing Authorization vulnerability in the Juniper Networks Junos Space Security Director allows an unauthenticated ne...
CVE-2025-59967HIGH7.1A NULL Pointer Dereference vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved...
CVE-2025-59964HIGH8.7A Use of Uninitialized Resource vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX4...
CVE-2025-59957HIGH7An Origin Validation Error vulnerability in an insufficient protected file of Juniper Networks Junos OS on EX4600 Series...
CVE-2025-52961HIGH7.1An Uncontrolled Resource Consumption vulnerability in the Connectivity Fault Management (CFM) daemon and the Connectivit...
CVE-2025-52960HIGH8.2A Buffer Copy without Checking Size of Input vulnerability in the Session Initialization Protocol (SIP) ALG of Juniper...
CVE-2025-11198HIGH7.4A Missing Authentication for Critical Function vulnerability in Juniper Networks Security Director Policy Enforcer allow...
CVE-2025-45095HIGH7.3Lavasoft Web Companion (also known as Ad-Aware WebCompanion) versions 8.9.0.1091 through 12.1.3.1037 installs the DCISer...
CVE-2025-32919HIGH7.8Use of an insecure temporary directory in the Windows License plugin for the Checkmk Windows Agent allows Privilege Esca...
CVE-2025-62228HIGH8.8Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted databas...
CVE-2025-11561HIGH8.8A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now