2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-66947MEDIUM6.5SQL injection vulnerability in krishanmuraiji SMS v.1.0, within the /studentms/admin/edit-class-detail.php via the editi...
CVE-2025-65885MEDIUM5.1An issue was discovered in the Delight Custom Firmware (CFW) for Nokia Symbian Belle devices on Nokia 808 (Delight v1.8)...
CVE-2025-64645HIGH7.4IBM Concert 1.0.0 through 2.1.0 could allow a local user to escalate their privileges due to a race condition of a symbo...
CVE-2025-36230MEDIUM5.4IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTM...
CVE-2025-36229MEDIUM4.3IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 could allow authenticated users to enumerate sensitive information of data du...
CVE-2025-36228LOW3.8IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user interface and backend API...
CVE-2025-25341HIGH7.5A vulnerability exists in the libxmljs 1.0.11 when parsing a specially crafted XML document. Accessing the internal _ref...
CVE-2025-36192HIGH7.1IBM DS8A00( R10.1) 10.10.106.0 and IBM DS8A00 ( R10.0) 10.1.3.010.2.45.0 and IBM DS8900F ( R9.4) 89.40.83.089.42.18.089....
CVE-2025-14687MEDIUM6.5IBM Db2 Intelligence Center 1.1.0, 1.1.1, 1.1.2 could allow an authenticated user to perform unauthorized actions due to...
CVE-2025-13915CRITICAL9.8IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanis...
CVE-2025-1721HIGH7.5IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due ...
CVE-2025-12771HIGH7.8IBM Concert 1.0.0 through 2.1.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A lo...
CVE-2025-67450HIGH7.8Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software ...
CVE-2025-59888MEDIUM6.7Improper quotation in search paths in the Eaton UPS Companion software installer could lead to arbitrary code execution ...
CVE-2025-59887HIGH8.6Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code exec...
CVE-2025-62578HIGH7.5DVP-12SE - Modbus/TCP Cleartext Transmission of Sensitive Information
CVE-2025-8075MEDIUM5.4Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io...
CVE-2025-68946MEDIUM5.4In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS.
CVE-2025-52601HIGH7.8Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io...
CVE-2025-52600HIGH7.2Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io...
CVE-2025-52599MEDIUM6.5Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io...
CVE-2025-52598LOW3.7Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io...
CVE-2025-68945MEDIUM5.3In Gitea before 1.21.2, an anonymous user can visit a private user's project.
CVE-2025-68944MEDIUM5.3Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package...
CVE-2025-68943MEDIUM5.3Gitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now