2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-56499MEDIUM6.5Incorrect access control in mihomo v1.19.11 allows authenticated attackers with low-level privileges to read arbitrary f...
CVE-2025-54771MEDIUM4.9A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader). The flaw occurs because t...
CVE-2025-54770MEDIUM4.9A vulnerability has been identified in the GRUB2 bootloader's network module that poses an immediate Denial of Service (...
CVE-2025-54321CRITICAL9.8In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an ema...
CVE-2025-54320MEDIUM4.3In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user function, leading to an email ...
CVE-2025-52639MEDIUM6.5HCL Connections is vulnerable to a sensitive information disclosure vulnerability which could allow a user to obtain sen...
CVE-2025-37163HIGH7.2A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave ...
CVE-2025-37160MEDIUM6.5A broken access control (BAC) vulnerability in the web-based management interface could allow an authenticated remote at...
CVE-2025-37159HIGH7.3A vulnerability in the web management interface of the AOS-CX OS user authentication service could allow an authenticate...
CVE-2025-37158HIGH8.8A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenti...
CVE-2025-37157HIGH8.8A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenti...
CVE-2025-37156MEDIUM6.8A platform-level denial-of-service (DoS) vulnerability exists in ArubaOS-CX software. Successful exploitation of this vu...
CVE-2025-37155HIGH7.8A vulnerability in the SSH restricted shell interface of the network management services allows improper access control ...
CVE-2025-64076HIGH7.5Multiple vulnerabilities exist in cbor2 through version 5.7.0 in the decode_definite_long_string() function of the C ext...
CVE-2025-63994Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2018-9206. Reason: This record is a duplicate of CVE-2018-9...
CVE-2025-63828MEDIUM6.1Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password re...
CVE-2025-63695CRITICAL9.8DzzOffice v2.3.7 and before is vulnerable to Arbitrary File Upload in /dzz/system/ueditor/php/controller.php.
CVE-2025-63694CRITICAL9.8DzzOffice v2.3.7 and before is vulnerable to SQL Injection in explorer/groupmanage.
CVE-2025-63514MEDIUM6.1kishan0725 Hospital Management System has a Cross-Site Scripting (XSS) vulnerability in appsearch.php via the email para...
CVE-2025-56643CRITICAL9.1Requarks Wiki.js 2.5.307 does not properly revoke or invalidate active JWT tokens when a user logs out. As a result, pre...
CVE-2025-63829HIGH7.5eProsima Fast-DDS v3.3 and before has an infinite loop vulnerability caused by integer overflow in the Time_t:: fraction...
CVE-2025-63513MEDIUM6.5kishan0725 Hospital Management System v4 has an Insecure Direct Object Reference (IDOR) vulnerability in the appointment...
CVE-2025-63512MEDIUM6.5kishan0725 Hospital Management System/ v4 is vulnerable to SQL Injection in admin-panel1.php, specifically in the deleti...
CVE-2025-63258MEDIUM6.5A remote command execution (RCE) vulnerability was discovered in all H3C ERG3/ERG5 series routers and XiaoBei series rou...
CVE-2025-61713MEDIUM4.4A Cleartext Storage of Sensitive Information in Memory vulnerability [CWE-316] in Fortinet FortiPAM 1.6.0, FortiPAM 1.5 ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now