2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-34416HIGH7.8MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe...
CVE-2025-34410HIGH7.11Panel versions 1.10.33 - 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the Change Username functi...
CVE-2025-34395HIGH7.5Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting ser...
CVE-2025-34394CRITICAL9.8Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting ser...
CVE-2025-34393CRITICAL9.8Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify t...
CVE-2025-34392CRITICAL9.8Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL def...
CVE-2025-13155HIGH8.5An improper permissions vulnerability was reported in Lenovo Baiying Client that could allow a local authenticated user ...
CVE-2025-13152HIGH7.8A potential DLL hijacking vulnerability was reported in Lenovo One Client during an internal security assessment that co...
CVE-2025-13125MEDIUM4.3Authorization Bypass Through User-Controlled Key vulnerability in Im Park Information Technology, Electronics, Press, Pu...
CVE-2025-12046HIGH7.8A DLL hijacking vulnerability was reported in the Lenovo App Store and Lenovo Browser applications that could allow a lo...
CVE-2025-8110HIGH8.8Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
CVE-2025-13127LOW3.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TAC Informa...
CVE-2025-13184CRITICAL9.8Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank passw...
CVE-2025-41358HIGH8.3Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulne...
CVE-2025-13953CRITICAL9.3Bypass vulnerability in the authentication method in the GTT Tax Information System application, related to the Active D...
CVE-2025-41732CRITICAL9.8An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary d...
CVE-2025-41730CRITICAL9.8An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary ...
CVE-2025-7073HIGH7.8A local privilege escalation vulnerability in Bitdefender Total Security versions prior to 27.0.47.241 allows low-privil...
CVE-2025-66675HIGH8.2Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. Thi...
CVE-2025-14390HIGH8.8The Video Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in version <= 5.0.4. This is due to ...
CVE-2025-9315MEDIUM6.3An unauthenticated device registration vulnerability, caused by Improperly Controlled Modification of Dynamically-Determ...
CVE-2025-66004MEDIUM5.7A Path Traversal vulnerability in usbmuxd allows local users to escalate to the service user.This issue affects usbmuxd:...
CVE-2025-1161HIGH7.1Incorrect Use of Privileged APIs vulnerability in NomySoft Information Technology Training and Consulting Inc. Nomysem a...
CVE-2025-14087CRITICAL9.8A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a...
CVE-2025-14082LOW2.7A flaw was found in Keycloak Admin REST (Representational State Transfer) API. This vulnerability allows information dis...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now