2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14688MEDIUM5.3IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could...
CVE-2025-56568HIGH7.5Assertion failure vulnerability in the PCO (Protocol Configuration Options) parser in the SMF (Session Management Functi...
CVE-2025-46115HIGH7.5An issue in open5gs v.2.7.3 allows a remote attacker to cause a denial of service via a crafted PDU Session Modification...
CVE-2025-71284CRITICAL9.8Synway SMG Gateway Management Software contains an OS command injection vulnerability in the RADIUS configuration endpoi...
CVE-2025-51846HIGH8.7CryptPad 2025.3.1 allows unbounded WebSocket frame flood. A remote, unauthenticated attacker can significantly degrade o...
CVE-2025-51850Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2025-51849Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2025-51847Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2025-14543CRITICAL9.1Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows ...
CVE-2025-13890Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-12494. Reason: This candidate is a ...
CVE-2025-14576HIGH7.8Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicio...
CVE-2025-13030CRITICAL9.8All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image ...
CVE-2025-50328HIGH7.3A vulnerability in B1 Free Archiver v1.5.86 allows files extracted from downloaded archives to bypass Windows Mark of th...
CVE-2025-56537MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 and fixed in v.7.0 allows attackers to execute...
CVE-2025-56536MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scri...
CVE-2025-56535MEDIUM6.1A cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or ...
CVE-2025-56534MEDIUM6.1A cross-site scripting (XSS) vulnerability in the custom authenticator driver of opennebula v6.10.0.1 allows attackers t...
CVE-2025-10503MEDIUM6.1The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a ...
CVE-2025-60889CRITICAL9.8Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to e...
CVE-2025-60887MEDIUM5.3An issue was discovered in Cista v0.15 and below. Insecure deserialization of untrusted input under certain conditions m...
CVE-2025-67223HIGH7.5The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs w...
CVE-2025-48431HIGH7.5Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apach...
CVE-2025-10539MEDIUM4.8Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can p...
CVE-2025-69428HIGH7.5An issue in Pro-Bit before v1.77.4 allows unauthenticated attackers to directly access sensitive directory and its subdi...
CVE-2025-69689HIGH8.8The Fan Control application V251 contains an improper privilege handling vulnerability in its Open File Dialog. The dial...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now