2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-69437HIGH8.7PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass ...
CVE-2025-10990HIGH7.5A flaw was found in REXML. A remote attacker could exploit inefficient regular expression (regex) parsing when processin...
CVE-2025-40932HIGH8.2Apache::SessionX versions through 2.01 for Perl create insecure session id. Apache::SessionX generates session ids inse...
CVE-2025-71057HIGH8.2Improper session management in D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME_1.00 allows attackers to execute a s...
CVE-2025-14343HIGH7.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dokuzsoft T...
CVE-2025-14511HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.2 before 18.7.5, 18.8 before 18.8.5, and 1...
CVE-2025-50180HIGH7.5esm.sh is a no-build content delivery network (CDN) for web development. In version 136, esm.sh is vulnerable to a full-...
CVE-2025-0976HIGH7.5Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager.This i...
CVE-2025-67752HIGH8.1OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio...
CVE-2025-33181HIGH8.8NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could ...
CVE-2025-33180HIGH8.8NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could ...
CVE-2025-33179HIGH8.8NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could ...
CVE-2025-1789HIGH7.8Local privilege escalation in Genetec Update Service. An authenticated, low-privileged, Windows user could exploit this ...
CVE-2025-14963HIGH7.8A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the abil...
CVE-2025-13776HIGH7.1Multiple Finka programs use hard-coded Firebird database credentials (shared across all instances of this software). A m...
CVE-2025-63409HIGH8.8Privilege escalation and improper access control in GCOM EPON 1GE C00R371V00B01 allows remote authenticated users to mod...
CVE-2025-67445HIGH7.5TOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of-service vulnerability in /cgi-bin/cstecgi.cgi. The CGI read...
CVE-2025-40541HIGH7.2An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor...
CVE-2025-40540HIGH7.2A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arb...
CVE-2025-40539HIGH7.2A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arb...
CVE-2025-40538HIGH7.2A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to crea...
CVE-2025-15589HIGH7.2A vulnerability was determined in MuYuCMS 2.7. Affected is the function delete_dir_file of the file application/admin/co...
CVE-2025-15386HIGH8.8The Responsive Lightbox & Gallery WordPress plugin before 2.6.1 is vulnerable to an Unauthenticated Stored-XSS attack du...
CVE-2025-13943HIGH8.8A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware ...
CVE-2025-9120HIGH8.6Improper Control of Generation of Code ('Code Injection') vulnerability in OpenText™ Carbonite Safe Server Backup allows...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now