2025 CVE Vulnerabilities

45,168 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14910MEDIUM6.5A vulnerability was detected in Edimax BR-6208AC 1.02. This impacts the function handle_retr of the component FTP Daemon...
CVE-2025-14909HIGH8.1A weakness has been identified in JeecgBoot up to 3.9.0. The impacted element is the function SysUserOnlineController of...
CVE-2025-13941HIGH8.8A local privilege escalation vulnerability exists in the Foxit PDF Reader/Editor Update Service. During plugin installat...
CVE-2025-14908HIGH8.1A security flaw has been discovered in JeecgBoot up to 3.9.0. The affected element is an unknown function of the file je...
CVE-2025-14900HIGH7.2A security vulnerability has been detected in CodeAstro Real Estate Management System 1.0. Affected is an unknown functi...
CVE-2025-14899HIGH7.2A weakness has been identified in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the f...
CVE-2025-14733CRITICAL9.8An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attac...
CVE-2025-11774HIGH8.2Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the software...
CVE-2025-64675CRITICAL9.6Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauth...
CVE-2025-14898HIGH7.2A security flaw has been discovered in CodeAstro Real Estate Management System 1.0. This affects an unknown function of ...
CVE-2025-14897HIGH7.2A vulnerability was identified in CodeAstro Real Estate Management System 1.0. The impacted element is an unknown functi...
CVE-2025-68422MEDIUM4.3Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated use...
CVE-2025-68398CRITICAL9.1Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration re...
CVE-2025-68390MEDIUM4.9Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with sna...
CVE-2025-68389MEDIUM6.5Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can allow a low-privileged authenticated user t...
CVE-2025-68387MEDIUM6.1Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an unauthenticated ...
CVE-2025-68386MEDIUM4.3Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated use...
CVE-2025-68385MEDIUM6.1Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated us...
CVE-2025-68279MEDIUM6.5Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the ...
CVE-2025-68388MEDIUM5.3Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excess...
CVE-2025-68384MEDIUM6.5Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated...
CVE-2025-68383MEDIUM6.5Improper Validation of Specified Index, Position, or Offset in Input (CWE-1285) in Filebeat Syslog parser and the Libbea...
CVE-2025-68382MEDIUM6.5Out-of-bounds read (CWE-125) allows an unauthenticated remote attacker to perform a buffer overflow (CAPEC-100) via the ...
CVE-2025-68381MEDIUM6.5Improper Bounds Check (CWE-787) in Packetbeat can allow a remote unauthenticated attacker to exploit a Buffer Overflow (...
CVE-2025-65046LOW3.1Microsoft Edge (Chromium-based) Spoofing Vulnerability

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now