2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-49194HIGH7.5The server supports authentication methods in which credentials are sent in plaintext over unencrypted channels. If an a...
CVE-2025-49188HIGH7.5The application sends user credentials as URL parameters instead of POST bodies, making it vulnerable to information gat...
CVE-2025-49184HIGH7.5A remote unauthorized attacker may gather sensitive information of the application, due to missing authorization of conf...
CVE-2025-49183HIGH7.5All communication with the REST API is unencrypted (HTTP), allowing an attacker to intercept traffic between an actor an...
CVE-2025-49181HIGH8.6Due to missing authorization of an API endpoint, unauthorized users can send HTTP GET requests to gather sensitive infor...
CVE-2025-6021HIGH7.5A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a ...
CVE-2025-0673HIGH7.5An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.10.8, 17.11 before 17.11.4, and ...
CVE-2025-4278HIGH8.7An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain cond...
CVE-2025-1516HIGH7.5An issue has been discovered in GitLab CE/EE affecting all versions from 8.7 before 17.10.8, 17.11 before 17.11.4, and 1...
CVE-2025-1478HIGH7.5An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 before 17.10.7, 17.11 before 17.11.3, and ...
CVE-2025-4613HIGH8.8Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to ac...
CVE-2025-5012HIGH8.8The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to arbitr...
CVE-2025-35978HIGH7.1Improper restriction of communication channel to intended endpoints issue exists in UpdateNavi V1.4 L10 to L33 and Updat...
CVE-2025-6009HIGH7.2A vulnerability was found in kiCode111 like-girl 5.2.0 and classified as critical. Affected by this issue is some unknow...
CVE-2025-6008HIGH7.2A vulnerability has been found in kiCode111 like-girl 5.2.0 and classified as critical. Affected by this vulnerability i...
CVE-2025-6007HIGH7.2A vulnerability, which was classified as critical, was found in kiCode111 like-girl 5.2.0. Affected is an unknown functi...
CVE-2025-6006HIGH7.2A vulnerability, which was classified as critical, has been found in kiCode111 like-girl 5.2.0. This issue affects some ...
CVE-2025-6005HIGH7.2A vulnerability classified as critical was found in kiCode111 like-girl 5.2.0. This vulnerability affects unknown code o...
CVE-2025-32465HIGH8.5A stored XSS vulnerability in RSTickets! component 1.9.12 - 3.3.0 for Joomla was discovered. It allows attackers to perf...
CVE-2025-25032HIGH7.5IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 could allow an a...
CVE-2025-6002HIGH7.2An unrestricted file upload vulnerability exists in the Product Image section of the VirtueMart backend. Authenticated a...
CVE-2025-6001HIGH8.3A Cross-Site Request Forgery (CSRF) vulnerability exists in the product image upload function of VirtueMart that bypasse...
CVE-2025-40915HIGH7Mojolicious::Plugin::CSRF 1.03 for Perl uses a weak random number source for generating CSRF tokens. That version of th...
CVE-2025-22874HIGH7.5Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. Th...
CVE-2025-49148HIGH7.3ClipShare is a lightweight and cross-platform tool for clipboard sharing. Prior to 3.8.5, ClipShare Server for Windows u...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now