2025 CVE Vulnerabilities

45,155 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-67013MEDIUM6.5The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not impleme...
CVE-2025-66738HIGH8.8An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a ...
CVE-2025-57403HIGH7.5Cola Dnslog v1.3.2 is vulnerable to Directory Traversal. When a DNS query for a TXT record is processed, the application...
CVE-2025-13158CRITICAL9.3Prototype pollution vulnerability in apidoc-core versions 0.2.0 and all subsequent versions allows remote attackers to m...
CVE-2025-67349MEDIUM6.1A cross-site scripting (XSS) vulnerability was identified in FluentCMS 1.2.3. After logging in as an admin and navigatin...
CVE-2025-66947MEDIUM6.5SQL injection vulnerability in krishanmuraiji SMS v.1.0, within the /studentms/admin/edit-class-detail.php via the editi...
CVE-2025-65885MEDIUM5.1An issue was discovered in the Delight Custom Firmware (CFW) for Nokia Symbian Belle devices on Nokia 808 (Delight v1.8)...
CVE-2025-64645HIGH7.4IBM Concert 1.0.0 through 2.1.0 could allow a local user to escalate their privileges due to a race condition of a symbo...
CVE-2025-36230MEDIUM5.4IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTM...
CVE-2025-36229MEDIUM4.3IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 could allow authenticated users to enumerate sensitive information of data du...
CVE-2025-36228LOW3.8IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user interface and backend API...
CVE-2025-25341HIGH7.5A vulnerability exists in the libxmljs 1.0.11 when parsing a specially crafted XML document. Accessing the internal _ref...
CVE-2025-36192HIGH7.1IBM DS8A00( R10.1) 10.10.106.0 and IBM DS8A00 ( R10.0) 10.1.3.010.2.45.0 and IBM DS8900F ( R9.4) 89.40.83.089.42.18.089....
CVE-2025-14687MEDIUM6.5IBM Db2 Intelligence Center 1.1.0, 1.1.1, 1.1.2 could allow an authenticated user to perform unauthorized actions due to...
CVE-2025-13915CRITICAL9.8IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanis...
CVE-2025-1721HIGH7.5IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due ...
CVE-2025-12771HIGH7.8IBM Concert 1.0.0 through 2.1.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A lo...
CVE-2025-67450HIGH7.8Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software ...
CVE-2025-59888MEDIUM6.7Improper quotation in search paths in the Eaton UPS Companion software installer could lead to arbitrary code execution ...
CVE-2025-59887HIGH8.6Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code exec...
CVE-2025-62578HIGH7.5DVP-12SE - Modbus/TCP Cleartext Transmission of Sensitive Information
CVE-2025-8075MEDIUM5.4Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io...
CVE-2025-68946MEDIUM5.4In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS.
CVE-2025-52601HIGH7.8Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io...
CVE-2025-52600HIGH7.2Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now