2025 CVE Vulnerabilities

45,181 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-2272HIGH7.3Uncontrolled Search Path Element vulnerability in Forcepoint FIE Endpoint allows Privilege Escalation, Code Injection, H...
CVE-2025-41403HIGH8.3Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection while fetching ...
CVE-2025-3836HIGH8.3Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the logon ev...
CVE-2025-3887HIGH8.8GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows ...
CVE-2025-3884HIGH7.5Cloudera Hue Ace Editor Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attac...
CVE-2025-3883HIGH8.8eCharge Hardy Barth cPH2 index.php Command Injection Remote Code Execution Vulnerability. This vulnerability allows netw...
CVE-2025-3882HIGH8.8eCharge Hardy Barth cPH2 nwcheckexec.php dest Command Injection Remote Code Execution Vulnerability. This vulnerability ...
CVE-2025-3881HIGH8.8eCharge Hardy Barth cPH2 check_req.php ntp Command Injection Remote Code Execution Vulnerability. This vulnerability all...
CVE-2025-3486HIGH8.8Allegra isZipEntryValide Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attac...
CVE-2025-3483HIGH7.8MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabil...
CVE-2025-3482HIGH7.8MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabil...
CVE-2025-3481HIGH7.8MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabil...
CVE-2025-2759HIGH7.8GStreamer Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local atta...
CVE-2025-5059HIGH7.2A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. This affects an unknown p...
CVE-2025-34025HIGH8.6The Versa Concerto SD-WAN orchestration platform is vulnerable to an privileges escalation and container escape vulnerab...
CVE-2025-47947HIGH7.5ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions ...
CVE-2025-34026HIGH7.5The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy ...
CVE-2025-45753HIGH7.2A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary P...
CVE-2025-44040HIGH7.2An issue in OrangeHRM v.5.7 allows an attacker to escalate privileges via UserService.php and the checkForOldHash functi...
CVE-2025-45752HIGH7.2A vulnerability in SeedDMS 6.0.32 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting t...
CVE-2025-3751HIGH7The component listed above contains a vulnerability that can be exploited by an attacker to perform a SQL Injection atta...
CVE-2025-2261HIGH7Stored XSS in TIBCO ActiveMatrix Administrator allows malicious data to appear to be part of the website and run within ...
CVE-2025-48063HIGH8.8XWiki is a generic wiki platform. In XWiki 16.10.0, required rights were introduced as a way to limit which rights a doc...
CVE-2025-48060HIGH7.5jq is a command-line JSON processor. In versions up to and including 1.7.1, a heap-buffer-overflow is present in functio...
CVE-2025-47291HIGH7.5containerd is an open-source container runtime. A bug was found in the containerd's CRI implementation where containerd,...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now