2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-49124HIGH8.4Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer fo...
CVE-2025-48988HIGH7.5Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: ...
CVE-2025-48976HIGH7.5Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons Fil...
CVE-2025-3526HIGH7.5SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 2...
CVE-2025-3602HIGH7.5Liferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through update 92, 7.3 GA thr...
CVE-2025-36632HIGH7.8In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could execute c...
CVE-2025-6122HIGH8.8A vulnerability, which was classified as critical, was found in code-projects Restaurant Order System 1.0. This affects ...
CVE-2025-5689HIGH8.5A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the fir...
CVE-2025-6115HIGH8.8A vulnerability was found in D-Link DIR-619L 2.06B01 and classified as critical. Affected by this issue is the function ...
CVE-2025-6114HIGH8.8A vulnerability has been found in D-Link DIR-619L 2.06B01 and classified as critical. Affected by this vulnerability is ...
CVE-2025-40728HIGH8.8SQL injection vulnerability in Customer Support System v1.0. This vulnerability allows an authenticated attacker to retr...
CVE-2025-3464HIGH8.4A race condition vulnerability exists in Armoury Crate. This vulnerability arises from a Time-of-check Time-of-use issue...
CVE-2025-6113HIGH8.8A vulnerability, which was classified as critical, was found in Tenda FH1203 2.0.1.6. Affected is the function fromadvse...
CVE-2025-6112HIGH8.8A vulnerability, which was classified as critical, has been found in Tenda FH1205 2.0.0.7. This issue affects the functi...
CVE-2025-4987HIGH8.7A stored Cross-site Scripting (XSS) vulnerability affecting Opportunity Management in Project Portfolio Manager from Rel...
CVE-2025-6111HIGH8.8A vulnerability classified as critical was found in Tenda FH1205 2.0.0.7(775). This vulnerability affects the function f...
CVE-2025-6110HIGH8.8A vulnerability classified as critical has been found in Tenda FH1201 1.2.0.14(408). This affects an unknown part of the...
CVE-2025-6105HIGH8.8A vulnerability has been found in jflyfox jfinal_cms 5.0.1 and classified as problematic. This vulnerability affects unk...
CVE-2025-6104HIGH8.8A vulnerability, which was classified as critical, was found in Wifi-soft UniBox Controller up to 20250506. This affects...
CVE-2025-6103HIGH8.8A vulnerability, which was classified as critical, has been found in Wifi-soft UniBox Controller up to 20250506. Affecte...
CVE-2025-6102HIGH8.8A vulnerability classified as critical was found in Wifi-soft UniBox Controller up to 20250506. Affected by this vulnera...
CVE-2025-6096HIGH8.8A vulnerability has been found in codesiddhant Jasmin Ransomware up to 1.0.1 and classified as critical. Affected by thi...
CVE-2025-6094HIGH8.8A vulnerability, which was classified as critical, has been found in qianfox FoxCMS up to 1.2.5. This issue affects the ...
CVE-2025-6091HIGH8.8A vulnerability was found in H3C GR-3000AX V100R007L50. It has been classified as critical. Affected is the function Upd...
CVE-2025-6090HIGH8.8A vulnerability was found in H3C GR-5400AX V100R009L50 and classified as critical. This issue affects the function Updat...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now