2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-36360MEDIUM5IBM UCD - IBM UrbanCode Deploy 7.1 through 7.1.2.27, 7.2 through 7.2.3.20, and 7.3 through 7.3.2.15 and IBM UCD - IBM De...
CVE-2025-14503HIGH8.6An overly-permissive IAM trust policy in the Harmonix on AWS framework may allow IAM principals in the same AWS account ...
CVE-2025-14148MEDIUM6.5IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 could allow an authenticated user with LLM integration configuration pri...
CVE-2025-13489MEDIUM5.9IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 IBM DevOps Deploy transmits data in clear text that could allow an attac...
CVE-2025-12035MEDIUM6.5An integer overflow condition exists in Bluetooth Host stack, within the bt_br_acl_recv routine a critical path for proc...
CVE-2025-65835MEDIUM6.2The Cordova plugin cordova-plugin-x-socialsharing (SocialSharing-PhoneGap-Plugin) for Android 6.0.4, registers an export...
CVE-2025-65213CRITICAL9.8MooreThreads torch_musa through all versions contains an unsafe deserialization vulnerability in torch_musa.utils.compar...
CVE-2025-65176HIGH7.5An issue was discovered in Dynatrace OneAgent before 1.325.47. When attempting to access a remote network share from a m...
CVE-2025-51962MEDIUM6.1A HTML Injection vulnerability in the comment section of the project page in MicroStudio 24.01.29 allows remote attacker...
CVE-2025-66440HIGH8.8An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext/acc...
CVE-2025-66439HIGH8.8An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext.acc...
CVE-2025-66438HIGH8.8A Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNext through 15.89.0 Print Format renderin...
CVE-2025-66437HIGH8.8An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext throug...
CVE-2025-66436MEDIUM4.3An SSTI (Server-Side Template Injection) vulnerability exists in the get_terms_and_conditions method of Frappe ERPNext t...
CVE-2025-14038HIGH7EDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints. Th...
CVE-2025-66435MEDIUM4.3An SSTI (Server-Side Template Injection) vulnerability exists in the get_contract_template method of Frappe ERPNext thro...
CVE-2025-66434HIGH8.8An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning_letter_text method of Frappe ERPNext th...
CVE-2025-65742HIGH8.2An unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11.0 allows attackers to...
CVE-2025-55901MEDIUM6.5TOTOLINK A3300R V17.0.0cu.596_B20250515 is vulnerable to command injection in the function NTPSyncWithHost via the host_...
CVE-2025-55893MEDIUM6.5TOTOLINK N200RE V9.3.5u.6437_B20230519 is vulnerable to command Injection in setOpModeCfg via hostName.
CVE-2025-11393HIGH8.7A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of...
CVE-2025-66963MEDIUM5.5An issue in Hitron HI3120 v.7.2.4.5.2b1 allows a local attacker to obtain sensitive information via the Logout option in...
CVE-2025-66844CRITICAL9.1In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is ...
CVE-2025-66843MEDIUM5.4grav before v1.7.49.5 has a Stored Cross-Site Scripting (Stored XSS) vulnerability in the page editing functionality. An...
CVE-2025-60786HIGH8.8A Zip Slip vulnerability in the import a Project component of iceScrum v7.54 Pro On-prem allows attackers to execute arb...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now