2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-6076HIGH8.8Partner Software's Partner Software application and Partner Web application do not sanitize files uploaded on the "repor...
CVE-2025-54796HIGH7.5Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows...
CVE-2025-54782HIGH8.8Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remo...
CVE-2025-54136HIGH8.8Cursor is a code editor built for programming with AI. In versions 1.2.4 and below, attackers can achieve remote and per...
CVE-2025-54132HIGH7.5Cursor is a code editor built for programming with AI. In versions below 1.3, Mermaid (which is used to render diagrams)...
CVE-2025-54131HIGH8.8Cursor is a code editor built for programming with AI. In versions below 1.3, an attacker can bypass the allow list in a...
CVE-2025-8480HIGH8Alpine iLX-507 Command Injection Remote Code Execution. This vulnerability allows network-adjacent attackers to execute ...
CVE-2025-8477HIGH7.4Alpine iLX-507 vCard Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows ...
CVE-2025-8476HIGH8Alpine iLX-507 TIDAL Improper Certificate Validation Vulnerability. This vulnerability allows network-adjacent attackers...
CVE-2025-8475HIGH7.4Alpine iLX-507 AVRCP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-...
CVE-2025-8472HIGH7.4Alpine iLX-507 vCard Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows ...
CVE-2025-5999HIGH7.2A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or...
CVE-2025-54595HIGH7.3Pearcleaner is a free, source-available and fair-code licensed mac app cleaner. The PearcleanerHelper is a privileged he...
CVE-2025-54593HIGH7.2FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.1 and below, an authenticated administrator user can ...
CVE-2025-54564HIGH7.8uploadsm in ChargePoint Home Flex 5.5.4.13 does not validate a user-controlled string for bz2 decompression, which allow...
CVE-2025-53012HIGH7.5MaterialX is an open standard for the exchange of rich material and look-development content across applications and ren...
CVE-2025-53011HIGH7.5MaterialX is an open standard for the exchange of rich material and look-development content across applications and ren...
CVE-2025-53010HIGH7.5MaterialX is an open standard for the exchange of rich material and look-development content across applications and ren...
CVE-2025-53009HIGH7.5MaterialX is an open standard for the exchange of rich material and look-development content across applications and ren...
CVE-2025-2824HIGH7.4IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, 9.0.0.1, and 9.5.0 could allow a remote attacker to condu...
CVE-2025-51504HIGH7.6Microweber CMS 2.0 is vulnerable to Cross Site Scripting (XSS)in the /projects/profile, homepage endpoint via the last n...
CVE-2025-52361HIGH7.8Insecure permissions in the script /etc/init.d/lighttpd in AK-Nord USB-Server-LXL Firmware v0.0.16 Build 2023-03-13 allo...
CVE-2025-52327HIGH7.8SQL Injection vulnerability in Restaurant Order System 1.0 allows a local attacker to obtain sensitive information via t...
CVE-2025-44139HIGH7.2Emlog Pro V2.5.7 is vulnerable to Unrestricted Upload of File with Dangerous Type via /emlog/admin/plugin.php?action=upl...
CVE-2025-45767HIGH7jose v6.0.10 was discovered to contain weak encryption. NOTE: this is disputed by a third party because the claim of "do...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now