2025 CVE Vulnerabilities

45,202 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13410CRITICAL9.8A vulnerability has been found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected is an unknown function of ...
CVE-2025-13147MEDIUM5.3Server-Side Request Forgery (SSRF) vulnerability in Progress MOVEit Transfer.This issue affects MOVEit Transfer: before ...
CVE-2025-65103HIGH8.8OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.9.5, an ...
CVE-2025-63932HIGH7.3D-Link Router DIR-868L A1 FW106KRb01.bin has an unauthenticated remote code execution vulnerability in the cgibin binary...
CVE-2025-63214MEDIUM6.5An issue was discovered in bridgetech VBC Server & Element Manager, firmware version 6.5.0-10 , 6.5.0-9, allowing unauth...
CVE-2025-63213CRITICAL9.8The QVidium Opera11 device (firmware version 2.9.0-Ax4x-opera11) is vulnerable to Remote Code Execution (RCE) due to imp...
CVE-2025-63212MEDIUM6.5GatesAir Flexiva-LX devices on firmware 1.0.13 and 2.0, including models LX100, LX300, LX600, and LX1000, expose sensiti...
CVE-2025-51663HIGH7.5A vulnerability found in IPRateLimit implementation of FileCodeBox up to 2.2 allows remote attackers to bypass ip-based ...
CVE-2025-51662MEDIUM5.4A stored cross-site scripting (XSS) vulnerability is found in the text sharing feature of FileCodeBox version 2.2 and ea...
CVE-2025-51661HIGH7.5A path Traversal vulnerability found in FileCodeBox v2.2 and earlier allows arbitrary file writes when application is co...
CVE-2025-36371MEDIUM6.5IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 are impacted by obtaining an information vulnerability in the database plan cache impl...
CVE-2025-65100MEDIUM6.9Isar is an integration system for automated root filesystem generation. In versions 0.11-rc1 and 0.11, defining ISAR_APT...
CVE-2025-65094HIGH8.8WBCE CMS is a content management system. Prior to version 1.6.4, a low-privileged user in WBCE CMS can escalate their pr...
CVE-2025-64759MEDIUM6.1Homarr is an open-source dashboard. Prior to version 1.43.3, stored XSS vulnerability exists, allowing the execution of ...
CVE-2025-63211MEDIUM6.1Stored cross-site scripting vulnerability in bridgetech VBC Server & Element Manager, firmware versions 6.5.0-9 thru 6.5...
CVE-2025-65099CRITICAL9.8Claude Code is an agentic coding tool. Prior to version 1.0.39, when running on a machine with Yarn 3.0 or above, Claude...
CVE-2025-65095CRITICAL9.4Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call eac...
CVE-2025-65089MEDIUM6.5XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to ver...
CVE-2025-65034HIGH8.1Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an improper authorization vulnerabil...
CVE-2025-65033HIGH8.1Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the poll ma...
CVE-2025-65032MEDIUM6.5Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference ...
CVE-2025-65031MEDIUM6.5Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an improper authorization flaw in th...
CVE-2025-65030HIGH7.1Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the comment...
CVE-2025-65029HIGH8.1Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference ...
CVE-2025-65028MEDIUM6.5Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now