2025 CVE Vulnerabilities

45,200 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-63685CRITICAL9.8Quark Cloud Drive v3.23.2 has a DLL Hijacking vulnerability. This vulnerability stems from the insecure loading of syste...
CVE-2025-62674HIGH7The affected product allows unauthenticated access to Real Time Streaming Protocol (RTSP) services, which may allow an a...
CVE-2025-25613HIGH7.5FS Inc S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch, 8 x Gigabit RJ45, with 2 x 1Gb SFP, Fanless. All versions before 2...
CVE-2025-55124MEDIUM6.1Improper neutralisation of input in Revive Adserver 6.0.0+ causes a reflected XSS attack in the banner-zone.php script.
CVE-2025-55123MEDIUM5.4Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be a...
CVE-2025-52671MEDIUM4.3Debug information disclosure in the SQL error message to in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes ...
CVE-2025-52670MEDIUM6.5Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete...
CVE-2025-52669MEDIUM4.3Insecure design policies in the user management system of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes no...
CVE-2025-52668MEDIUM5.4Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier version...
CVE-2025-52667MEDIUM5.4Missing JSON Content-Type header in a script in Revive Adserver 6.0.1 and 5.5.2 and earlier versions causes a stored XSS...
CVE-2025-52666LOW2.7Improper neutralisation of format characters in the settings of Revive Adserver 5.5.2 and 6.0.1 and earlier versions cau...
CVE-2025-48987MEDIUM6.1Improper Neutralization of Input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes a potential reflected XS...
CVE-2025-48986HIGH8.8Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change othe...
CVE-2025-35029MEDIUM5.4Medical Informatics Engineering Enterprise Health has a stored cross site scripting vulnerability that allows an authent...
CVE-2025-63700Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2025-55128MEDIUM6.5HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in th...
CVE-2025-55127MEDIUM5.4HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the userna...
CVE-2025-55126MEDIUM6.5HackerOne community member Dang Hung Vi (vidang04) has reported a stored XSS vulnerability involving the navigation box ...
CVE-2025-10571CRITICAL9.6Authentication Bypass Using an Alternate Path or Channel vulnerability in ABB ABB Ability Edgenius.This issue affects AB...
CVE-2025-64524MEDIUM5.5cups-filters contains backends, filters, and other software required to get the cups printing service working on operati...
CVE-2025-63889HIGH7.5The fetch function in file thinkphp\library\think\Template.php in ThinkPHP 5.0.24 allows attackers to read arbitrary fil...
CVE-2025-63888CRITICAL9.8The read function in file thinkphp\library\think\template\driver\File.php in ThinkPHP 5.0.24 contains a remote code exec...
CVE-2025-64428CRITICAL9.8Dataease is an open source data visualization analysis tool. Versions prior to 2.10.17 are vulnerable to JNDI injection....
CVE-2025-64185MEDIUM6.9Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writ...
CVE-2025-64027MEDIUM6.1Snipe-IT v8.3.4 (build 20218) contains a reflected cross-site scripting (XSS) vulnerability in the CSV Import workflow. ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now