2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-54591HIGH7.5FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below expose information about feeds and tags of d...
CVE-2025-45376HIGH7.8Dell Repository Manager (DRM), versions 3.4.7 and 3.4.8, contains an Improper Handling of Insufficient Permissions or Pr...
CVE-2025-34235HIGH7.8Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 2...
CVE-2025-34234HIGH7.5Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 2...
CVE-2025-34231HIGH8.6Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 2...
CVE-2025-34228HIGH8.6Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 2...
CVE-2025-34225HIGH8.6Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 2...
CVE-2025-34209HIGH7.2Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 22.0.862 and Application prior to 20.0.2014 (VA and...
CVE-2025-35030HIGH8.8Medical Informatics Engineering Enterprise Health has a cross site request forgery vulnerability that allows an unauthen...
CVE-2025-57424HIGH7.3A stored cross-site scripting (XSS) vulnerability exists in the MyCourts v3 application within the LTA number profile fi...
CVE-2025-41252HIGH7.5Description: VMware NSX contains a username enumeration vulnerability. An unauthenticated malicious actor may exploit th...
CVE-2025-41251HIGH8.1VMware NSX contains a weak password recovery mechanism vulnerability. An unauthenticated malicious actor may exploit thi...
CVE-2025-57483HIGH8.1A reflected cross-site scripting (XSS) vulnerability in tawk.to chatbox widget v4 allows attackers to execute arbitrary ...
CVE-2025-41250HIGH8.5VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on ...
CVE-2025-7104HIGH7.5A mass assignment vulnerability exists in danny-avila/librechat, affecting all versions. This vulnerability allows attac...
CVE-2025-56234HIGH7.5AT_NA2000 from Nanda Automation Technology vendor has a denial-of-service vulnerability. For the processing of TCP RST p...
CVE-2025-56233HIGH7.5Openindiana, kernel SunOS 5.11 has a denial of service vulnerability. For the processing of TCP packets with RST or SYN ...
CVE-2025-51495HIGH7.5An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially cr...
CVE-2025-41244HIGH7.8VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with...
CVE-2025-41246HIGH7.6VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls...
CVE-2025-57516HIGH8.2OS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b allowing attackers to e...
CVE-2025-56449HIGH8.2A security vulnerability was identified in Obsidian Scheduler's REST API 5.0.0 thru 6.3.0. If an account is locked out d...
CVE-2025-9648HIGH8.7A vulnerability in the CivetWeb library's function mg_handle_form_request allows remote attackers to trigger a denial of...
CVE-2025-8868HIGH8.8In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain acc...
CVE-2025-6724HIGH8.8In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain acc...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now