2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-48889HIGH7.5Gradio is an open-source Python package that allows quick building of demos and web application for machine learning mod...
CVE-2025-48881HIGH8.3Valtimo is a platform for Business Process Automation. In versions starting from 11.0.0.RELEASE to 11.3.3.RELEASE and 12...
CVE-2025-41235HIGH8.6Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies.
CVE-2025-48477HIGH8.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application's logic requires...
CVE-2025-48476HIGH8.8FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when adding and editing user rec...
CVE-2025-44906HIGH7.8jhead v3.08 was discovered to contain a heap-use-after-free via the ProcessFile function at jhead.c.
CVE-2025-44905HIGH8.8hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5Z__filter_scaleoffset function.
CVE-2025-44904HIGH8.8hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function.
CVE-2025-44614HIGH7.5Tinxy WiFi Lock Controller v1 RF was discovered to store users' sensitive information, including credentials and mobile ...
CVE-2025-5307HIGH7.8Santesoft Sante DICOM Viewer Pro contains a memory corruption vulnerability. A local attacker could exploit this issue t...
CVE-2025-31189HIGH8.2A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 1...
CVE-2025-5328HIGH8.8A vulnerability was found in chshcms mccms 2.7. It has been declared as critical. This vulnerability affects the functio...
CVE-2025-5327HIGH8.8A vulnerability was found in chshcms mccms 2.7. It has been classified as critical. This affects the function index of t...
CVE-2025-5326HIGH8.8A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0 and classified as cr...
CVE-2025-2518HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 is v...
CVE-2025-46701HIGH7.3Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of ...
CVE-2025-46823HIGH8openmrs-module-fhir2 provides the FHIR REST API and related services for OpenMRS, an open medical records system. In ver...
CVE-2025-48475HIGH8.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the System does not provide a ch...
CVE-2025-46722HIGH7.3vLLM is an inference and serving engine for large language models (LLMs). In versions starting from 0.7.0 to before 0.9....
CVE-2025-48474HIGH8.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application incorrectly chec...
CVE-2025-48472HIGH8.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, there is no check to ensure that...
CVE-2025-48390HIGH7.2FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to code ...
CVE-2025-48389HIGH7.2FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to deser...
CVE-2025-45474HIGH7.3maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings.
CVE-2025-5334HIGH7.5Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Des...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now