2025 CVE Vulnerabilities

45,180 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-41235HIGH8.6Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies.
CVE-2025-48477HIGH8.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application's logic requires...
CVE-2025-48476HIGH8.8FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when adding and editing user rec...
CVE-2025-44906HIGH7.8jhead v3.08 was discovered to contain a heap-use-after-free via the ProcessFile function at jhead.c.
CVE-2025-44905HIGH8.8hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5Z__filter_scaleoffset function.
CVE-2025-44904HIGH8.8hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function.
CVE-2025-44614HIGH7.5Tinxy WiFi Lock Controller v1 RF was discovered to store users' sensitive information, including credentials and mobile ...
CVE-2025-5307HIGH7.8Santesoft Sante DICOM Viewer Pro contains a memory corruption vulnerability. A local attacker could exploit this issue t...
CVE-2025-31189HIGH8.2A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 1...
CVE-2025-5328HIGH8.8A vulnerability was found in chshcms mccms 2.7. It has been declared as critical. This vulnerability affects the functio...
CVE-2025-5327HIGH8.8A vulnerability was found in chshcms mccms 2.7. It has been classified as critical. This affects the function index of t...
CVE-2025-5326HIGH8.8A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0 and classified as cr...
CVE-2025-2518HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 is v...
CVE-2025-46701HIGH7.3Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of ...
CVE-2025-46823HIGH8openmrs-module-fhir2 provides the FHIR REST API and related services for OpenMRS, an open medical records system. In ver...
CVE-2025-48475HIGH8.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the System does not provide a ch...
CVE-2025-46722HIGH7.3vLLM is an inference and serving engine for large language models (LLMs). In versions starting from 0.7.0 to before 0.9....
CVE-2025-48474HIGH8.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application incorrectly chec...
CVE-2025-48472HIGH8.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, there is no check to ensure that...
CVE-2025-48390HIGH7.2FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to code ...
CVE-2025-48389HIGH7.2FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to deser...
CVE-2025-45474HIGH7.3maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings.
CVE-2025-5334HIGH7.5Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Des...
CVE-2025-48045HIGH8.7An unauthenticated HTTP GET request to the /client.php endpoint will disclose the default administrator user credentials...
CVE-2025-4687HIGH7.2In Teltonika Networks Remote Management System (RMS), it is possible to perform account pre-hijacking by misusing the in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now