2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-48060HIGH7.5jq is a command-line JSON processor. In versions up to and including 1.7.1, a heap-buffer-overflow is present in functio...
CVE-2025-47291HIGH7.5containerd is an open-source container runtime. A bug was found in the containerd's CRI implementation where containerd,...
CVE-2025-46822HIGH7.7OsamaTaher/Java-springboot-codebase is a collection of Java and Spring Boot code snippets, applications, and projects. P...
CVE-2025-5030HIGH8.1A vulnerability was found in Ackites KillWxapkg up to 2.4.1. It has been declared as critical. This vulnerability affect...
CVE-2025-4416HIGH7.5Allocation of Resources Without Limits or Throttling vulnerability in Drupal Events Log Track allows Excessive Allocatio...
CVE-2025-20256HIGH7.2A vulnerability in the web-based management interface of Cisco Secure Network Analytics Manager and Cisco Secure Network...
CVE-2025-20152HIGH8.6A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthen...
CVE-2025-20113HIGH7.1A vulnerability in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to elevate privileges...
CVE-2025-4008HIGH8.8The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer ...
CVE-2025-48207HIGH8.6The reint_downloadmanager extension through 5.0.0 for TYPO3 allows Insecure Direct Object Reference.
CVE-2025-48205HIGH8.6The sr_feuser_register extension through 12.4.8 for TYPO3 allows Insecure Direct Object Reference.
CVE-2025-48201HIGH8.6The ns_backup extension through 13.0.0 for TYPO3 has a Predictable Resource Location.
CVE-2025-27998HIGH8.4An issue in Valvesoftware Steam Client Steam Client 1738026274 allows attackers to escalate privileges via a crafted exe...
CVE-2025-27997HIGH8.4An issue in Blizzard Battle.net v2.40.0.15267 allows attackers to escalate privileges via placing a crafted shell script...
CVE-2025-48416HIGH8.1An OpenSSH daemon listens on TCP port 22. There is a hard-coded entry in the "/etc/shadow" file in the firmware image fo...
CVE-2025-40775HIGH7.5When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it. If the TSIG conta...
CVE-2025-1416HIGH7In Proget MDM, a low-privileged user can retrieve passwords for managed devices and subsequently use functionalities res...
CVE-2025-4803HIGH7.2The Glossary by WPPedia – Best Glossary plugin for WordPress plugin for WordPress is vulnerable to PHP Object Injection ...
CVE-2025-48413HIGH7.7The `/etc/passwd` and `/etc/shadow` files reveal hard-coded password hashes for the operating system "root" user. The cr...
CVE-2025-1712HIGH8.8Argument injection in special agent configuration in Checkmk <2.4.0p1, <2.3.0p32, <2.2.0p42 and 2.1.0 allows authenticat...
CVE-2025-4998HIGH7.1A vulnerability has been found in H3C Magic R200G up to 100R002 and classified as problematic. Affected by this vulnerab...
CVE-2025-4997HIGH7.1A vulnerability, which was classified as problematic, was found in H3C R2+ProG up to 200R004. Affected is the function U...
CVE-2025-4364HIGH8.7The affected products could allow an unauthenticated attacker to access system information that could enable further acc...
CVE-2025-48391HIGH7.5In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API
CVE-2025-37991HIGH7.8In the Linux kernel, the following vulnerability has been resolved: parisc: Fix double SIGFPE crash Camm noticed that ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now