2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-62317LOW2.6HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive...
CVE-2025-62316LOW2.3HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured...
CVE-2025-62313MEDIUM5.4HCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced. This m...
CVE-2025-62312LOW3HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication. Use of basic autho...
CVE-2025-62311MEDIUM4.3HCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels. Th...
CVE-2025-62310MEDIUM5.4HCL AION is affected by a vulnerability where encryption is not enforced for certain data transmissions or operations. T...
CVE-2025-62309LOW2.6HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields. This may ...
CVE-2025-62308MEDIUM5.1HCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposed. Exposure of such ...
CVE-2025-62305MEDIUM5.1HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions, potentially resul...
CVE-2025-69443MEDIUM6.3Remote Code Execution in coleam00 Archon 0.1.0. A crafted HTML page, when accessed by a victim, can execute commands, ru...
CVE-2025-62628HIGH7Unsafe OpenSSL initialization within some AMD optional tools may allow a local user-privileged attacker to inject a mali...
CVE-2025-62625MEDIUM6Improper privilege management in the KVM key download component could allow an attacker to swap tokens and download sens...
CVE-2025-62619MEDIUM6.3Missing authentication in the KVM key download endpoint could allow an unauthenticated attacker with knowledge of the ex...
CVE-2025-15025HIGH8.8Authorization bypass through User-Controlled key vulnerability in Yordam Information Technology Consulting, Training and...
CVE-2025-12008HIGH8.8Authorization bypass through User-Controlled key vulnerability in APPYAP Technology and Information Inc. Yaay Social Med...
CVE-2025-68421HIGH8.7Comarch ERP Optima client makes use of a hard-coded password for a database user. These credentials cannot be changed. I...
CVE-2025-68420HIGH7.5Comarch ERP Optima client connects to a database using a high privileged account regardless of an application account to...
CVE-2025-11024CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce So...
CVE-2025-15345MEDIUM6.1The MapGeo – Interactive Geo Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'map' par...
CVE-2025-14870HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and...
CVE-2025-14869HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and...
CVE-2025-13874MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and...
CVE-2025-12669MEDIUM5.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.9.7, 18.10 before 18.10.6, an...
CVE-2025-27853HIGH7.3The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed. The WDU we...
CVE-2025-27852MEDIUM5The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) attack...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now