2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14871HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and...
CVE-2025-11395MEDIUM5.5A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create ...
CVE-2025-66974HIGH7.5An issue in Prolink 13A Smart Plug Model Version: DS-3202M-UKv3 Wi-Fi and Application Version mEzee 2.6.7 allows attacke...
CVE-2025-5802MEDIUM5.3The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of use...
CVE-2025-13166LOW3.7The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered us...
CVE-2025-24890MEDIUM6.8gitoxide is an implementation of git written in Rust. Prior to 0.13.3, the gix-sec crate on Windows incorrectly treats r...
CVE-2025-26790LOW3.7Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote Denial of Service via an out-of-bounds memo...
CVE-2025-68624MEDIUM4.3N-able Mail Assure through April 2026 contains a design-level authorization flaw that allows an authenticated SMTP user ...
CVE-2025-64031LOW2.5libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field...
CVE-2025-63842MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allows a remote ...
CVE-2025-70820LOW3.5Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.
CVE-2025-70819MEDIUM6.3Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /etc/shadow in a container via ".." manipulations such as ...
CVE-2025-64059LOW1.8Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is ...
CVE-2025-45480LOW3Floodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary.
CVE-2025-69904MEDIUM4.9Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an administrator to read arbitrary files on t...
CVE-2025-15679HIGH7.3Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a pa...
CVE-2025-15695LOW3.5The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the ...
CVE-2025-57231HIGH7.5Path Traversal in avatar attachments in Docmost v0.21.0 allows an unauthenticated malicious actor to disclose local file...
CVE-2025-51619MEDIUM5.5A vulnerability in the Thesycon DPC Latency Checker driver (dpc.sys) thru 1.4.0 allows local unprivileged users to cause...
CVE-2025-71418MEDIUM5.3PocketMine-MP versions before 5.25.2 fail to limit the explode() function in packet parsing, allowing malicious clients ...
CVE-2025-71417MEDIUM6.5PocketMine-MP before 5.32.1 fails to validate uniqueness of pack UUIDs in ResourcePackClientResponsePacket STATUS_SEND_P...
CVE-2025-3271MEDIUM4.8Documentum Webtop versions prior to 16.7.1 software is vulnerable to an XSS
CVE-2025-46808MEDIUM6.8An Insertion of Sensitive Information into Log File vulnerability in SUSE neuvector manager exposes sensitive informatio...
CVE-2025-7062MEDIUM5.2A stored cross-site scripting (XSS) vulnerability has been identified in the H5P module `h5p-nodejs-library` by Lumi Edu...
CVE-2025-15690MEDIUM6.8The Content Mask WordPress plugin before 1.8.5.6 does not properly sanitise and escape content submitted with a post bef...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now