2025 CVE Vulnerabilities

45,185 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-65278HIGH7.5An issue was discovered in file users.json in GroceryMart commit 21934e6 (2020-10-23) allowing unauthenticated attackers...
CVE-2025-65276CRITICAL9.8An unauthenticated administrative access vulnerability exists in the open-source HashTech project (https://github.com/he...
CVE-2025-50433CRITICAL9.8An issue was discovered in imonnit.com (2025-04-24) allowing malicious actors to gain escalated privileges via crafted p...
CVE-2025-13611MEDIUM5.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.5.5 and 18.6 before 18.6.3 tha...
CVE-2025-12653MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18.5 before 18.5.3, and 1...
CVE-2025-12571HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.4.5, 18.5 before 18.5.3, and ...
CVE-2025-66028HIGH8.2OneUptime is a solution for monitoring and managing online services. Prior to version 8.0.5567, OneUptime is vulnerable ...
CVE-2025-65966HIGH8.1OneUptime is a solution for monitoring and managing online services. In version 9.0.5598, a low-permission user can crea...
CVE-2025-65681LOW3.3An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers ...
CVE-2025-65676MEDIUM5.4Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbi...
CVE-2025-65675MEDIUM5.4Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbi...
CVE-2025-65672HIGH7.5Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows unauthorized share and invite access to course sett...
CVE-2025-65669CRITICAL9.1An issue was discovered in classroomio 0.1.13. Student accounts are able to delete courses from the Explore page without...
CVE-2025-26155CRITICAL9.8NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability...
CVE-2025-64130CRITICAL9.8Zenitel TCIV-3+ is vulnerable to a reflected cross-site scripting vulnerability, which could allow a remote attacker to...
CVE-2025-64129HIGH7.6Zenitel TCIV-3+ is vulnerable to an out-of-bounds write vulnerability, which could allow a remote attacker to crash the...
CVE-2025-64128CRITICAL10An OS command injection vulnerability exists due to incomplete validation of user-supplied input. Validation fails to e...
CVE-2025-64127CRITICAL10An OS command injection vulnerability exists due to insufficient sanitization of user-supplied input. The application a...
CVE-2025-64126CRITICAL10An OS command injection vulnerability exists due to improper input validation. The application accepts a parameter dire...
CVE-2025-55471HIGH7.5Incorrect access control in the getUserFormData function of youlai-boot v2.21.1 allows attackers to access sensitive inf...
CVE-2025-55469CRITICAL9.8Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and access the Administrator bac...
CVE-2025-2486HIGH8.8The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, p...
CVE-2025-20373LOW2.7In Splunk Add-on for Palo Alto Networks versions below 2.0.2, the add-on exposes client secrets in plain text in the _in...
CVE-2025-13084HIGH7.6The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys. ...
CVE-2025-11461HIGH8.8Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user-controlled parameters int...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now