2025 CVE Vulnerabilities

45,168 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-65041CRITICAL9.8Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-65037CRITICAL10Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to exe...
CVE-2025-64677HIGH8.2Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience all...
CVE-2025-64676HIGH7.2'.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network.
CVE-2025-64663HIGH8.8Custom Question Answering Elevation of Privilege Vulnerability
CVE-2025-34452HIGH8.7Streama versions 1.10.0 through 1.10.5 and prior to commit b7c8767 contain a combination of path traversal and server-si...
CVE-2025-34451HIGH7.8rofl0r/proxychains-ng versions up to and including 4.17 and prior to commit cc005b7 contain a stack-based buffer overflo...
CVE-2025-34450HIGH7.8merbanan/rtl_433 versions up to and including 25.02 and prior to commit 25e47f8 contain a stack-based buffer overflow vu...
CVE-2025-34449CRITICAL9.1Genymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24, contain a buffer overflow vulnerability i...
CVE-2025-13427MEDIUM6.9An authentication bypass vulnerability in Google Cloud Dialogflow CX Messenger allowed unauthenticated users to interact...
CVE-2025-68161MEDIUM4.8The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of...
CVE-2025-67653HIGH7.5Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to determine the existence o...
CVE-2025-63951HIGH7.5An insecure deserialization vulnerability exists in the rss-mp3.php script of the MiczFlor RPi-Jukebox-RFID project thro...
CVE-2025-63950HIGH7.5An insecure deserialization vulnerability exists in the download.php script of the to3k Twittodon application through co...
CVE-2025-63949MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability in yohanawi Hotel Management System (commit 87e004a) allows a remot...
CVE-2025-63948MEDIUM5.4A SQL Injection vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute ar...
CVE-2025-63947MEDIUM5.4A Reflected Cross-Site Scripting (XSS) vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An ...
CVE-2025-62004HIGH7.7BullWall Server Intrusion Protection (SIP) services are initialized after login services during system startup. A local,...
CVE-2025-62003HIGH7.7BullWall Server Intrusion Protection has a noticeable configuration-dependent delay before the MFA check for RDP connect...
CVE-2025-62002HIGH8.1BullWall Ransomware Containment considers the number of files modified to trigger detection. An authenticated attacker c...
CVE-2025-62001HIGH8.8BullWall Ransomware Containment supports configurable file and directory exclusions such as '$RECYCLE.BIN' to balance mo...
CVE-2025-62000HIGH7.1BullWall Ransomware Containment may not always detect an encrypted file. This issue affects a specific file inspection m...
CVE-2025-59529MEDIUM5.5Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions...
CVE-2025-53710HIGH7.5Due to a product misconfiguration in certain deployment types, it was possible from different pods in the same namespace...
CVE-2025-46268HIGH8.8Advantech WebAccess/SCADA  is vulnerable to SQL injection, which may allow an attacker to execute arbitrary SQL commands...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now