2025 CVE Vulnerabilities

45,202 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-64185MEDIUM6.9Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writ...
CVE-2025-64027MEDIUM6.1Snipe-IT v8.3.4 (build 20218) contains a reflected cross-site scripting (XSS) vulnerability in the CSV Import workflow. ...
CVE-2025-63848MEDIUM6.1Stored cross site scripting (xss) vulnerability in SWISH prolog thru 2.2.0 allowing attackers to execute arbitrary code ...
CVE-2025-62724MEDIUM4.3Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, users can craft a "Time of Check to Time...
CVE-2025-62709HIGH8.8ClipBucket v5 is an open source video sharing platform. In ClipBucket version 5.5.2, a change to network.class.php cause...
CVE-2025-52410CRITICAL9.8Institute-of-Current-Students v1.0 contains a time-based blind SQL injection vulnerability in the mydetailsstudent.php e...
CVE-2025-13437MEDIUM5.6When zx is invoked with --prefer-local=<path>, the CLI creates a symlink named ./node_modules pointing to <path>/node_mo...
CVE-2025-12121HIGH7.3Lite XL versions 2.1.8 and prior contain a vulnerability in the system.exec function, which allowed arbitrary command ex...
CVE-2025-12120HIGH7.3Lite XL versions 2.1.8 and prior automatically execute the .lite_project.lua file when opening a project directory, with...
CVE-2025-62875MEDIUM5.5An Improper Check for Unusual or Exceptional Conditions vulnerability in OpenSMTPD allows local users to crash OpenSMTPD...
CVE-2025-62731MEDIUM4.8SOPlanning is vulnerable to Stored XSS in /feries endpoint. Malicious attacker with access to public holidays feature is...
CVE-2025-62730HIGH8.8SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to...
CVE-2025-62729MEDIUM5.4SOPlanning is vulnerable to Stored XSS in /status endpoint. Malicious attacker with an account can inject arbitrary HTML...
CVE-2025-62297MEDIUM5.4SOPlanning is vulnerable to Stored XSS in /projets endpoint. Malicious attacker with medium privileges can inject arbitr...
CVE-2025-62296MEDIUM5.4SOPlanning is vulnerable to Stored XSS in /taches endpoint. Malicious attacker with medium privileges can inject arbitra...
CVE-2025-62295MEDIUM5.4SOPlanning is vulnerable to Stored XSS in /groupe_form endpoint. Malicious attacker with medium privileges can inject ar...
CVE-2025-62294HIGH7.5SOPlanning is vulnerable to Predictable Generation of Password Recovery Token. Due to weak mechanism of generating recov...
CVE-2025-62293MEDIUM5.4SOPlanning is vulnerable to Broken Access Control in /status endpoint. Due to lack of permission checks in Project Statu...
CVE-2025-60738CRITICAL9.8An issue in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before Logic Version v6.00 - 2025_07_21 and before ...
CVE-2025-60737MEDIUM6.1Cross Site Scripting vulnerability in Ilevia EVE X1 Server Firmware Version<= 4.7.18.0.eden:Logic Version<=6.00 - 2025_0...
CVE-2025-36161MEDIUM5.9IBM Concert 1.0.0 through 2.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to ...
CVE-2025-34320CRITICAL9.3BASIS BBj versions prior to 25.00 contain a Jetty-served web endpoint that fails to properly validate or canonicalize in...
CVE-2025-13425LOW1.9A bug in the filesystem traversal fallback path causes fs/diriterate/diriterate.go:Next() to overindex an empty slice wh...
CVE-2025-65226MEDIUM4.3Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the deviceId parameter in /goform/saveParentControlInfo.
CVE-2025-65223MEDIUM4.3Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the urls parameter of /goform/saveParentControlInfo.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now