2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13829HIGH8.6Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private...
CVE-2025-11699HIGH7.1nopCommerce v4.70 and prior, and version 4.80.3, does not invalidate session cookies after logout or session termination...
CVE-2025-10101HIGH7.8Heap buffer out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed Mach-O file may allow Local Ex...
CVE-2025-64030MEDIUM5.4Eximbills Enterprise 4.1.5 (Built on 2020-10-30) is vulnerable to authenticated stored cross-site scripting (CWE-79) via...
CVE-2025-63531CRITICAL9.8A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogin.php component. The...
CVE-2025-63529HIGH8.8A session fixation vulnerability exists in Blood Bank Management System 1.0 in login.php that allows an attacker to set ...
CVE-2025-63528MEDIUM5.4A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the blooddinfo.php comp...
CVE-2025-63527MEDIUM5.4A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the updateprofile.php a...
CVE-2025-63526MEDIUM5.4A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System within the abs.php component. The ...
CVE-2025-63525HIGH8.8An issue was discovered in Blood Bank Management System 1.0 allowing authenticated attackers to perform actions with esc...
CVE-2025-63523MEDIUM6.5FeehiCMS version 2.1.1 fails to enforce server-side immutability for parameters that are presented to clients as "read-o...
CVE-2025-63522MEDIUM4.6Reverse Tabnabbing vulnerability in FeehiCMS 2.1.1 in the Comments Management function
CVE-2025-63520MEDIUM6.1Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 via the id parameter of the User Update function (?r=user%2Fu...
CVE-2025-13129MEDIUM4.3Improper Enforcement of Behavioral Workflow vulnerability in Seneka Software Hardware Information Technology Trade Contr...
CVE-2025-49643MEDIUM6.5An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending sp...
CVE-2025-49642MEDIUM5.9Library loading on AIX Zabbix Agent builds can be hijacked by local users with write access to the /home/cecuser directo...
CVE-2025-27232MEDIUM4.9An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver le...
CVE-2025-12106CRITICAL9.1Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-...
CVE-2025-58408MEDIUM5.9Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger reads of stale data...
CVE-2025-13296MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Tekrom Technology Inc. T-Soft E-Commerce allows Cross Site Request Fo...
CVE-2025-8045MEDIUM4Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver al...
CVE-2025-6349MEDIUM5.1Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver al...
CVE-2025-59789HIGH7.5Uncontrolled recursion in the json2pb component in Apache bRPC (version < 1.15.0) on all platforms allows remote attacke...
CVE-2025-41070MEDIUM4.8Reflected Cross-site Scripting (XSS) vulnerability in Sanoma's Clickedu. This vulnerability allows an attacker to execut...
CVE-2025-2879MEDIUM5.1Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd A...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now