2025 CVE Vulnerabilities

45,181 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-46822HIGH7.7OsamaTaher/Java-springboot-codebase is a collection of Java and Spring Boot code snippets, applications, and projects. P...
CVE-2025-5030HIGH8.1A vulnerability was found in Ackites KillWxapkg up to 2.4.1. It has been declared as critical. This vulnerability affect...
CVE-2025-4416HIGH7.5Allocation of Resources Without Limits or Throttling vulnerability in Drupal Events Log Track allows Excessive Allocatio...
CVE-2025-20256HIGH7.2A vulnerability in the web-based management interface of Cisco Secure Network Analytics Manager and Cisco Secure Network...
CVE-2025-20152HIGH8.6A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthen...
CVE-2025-20113HIGH7.1A vulnerability in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to elevate privileges...
CVE-2025-4008HIGH8.8The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer ...
CVE-2025-48207HIGH8.6The reint_downloadmanager extension through 5.0.0 for TYPO3 allows Insecure Direct Object Reference.
CVE-2025-48205HIGH8.6The sr_feuser_register extension through 12.4.8 for TYPO3 allows Insecure Direct Object Reference.
CVE-2025-48201HIGH8.6The ns_backup extension through 13.0.0 for TYPO3 has a Predictable Resource Location.
CVE-2025-27998HIGH8.4An issue in Valvesoftware Steam Client Steam Client 1738026274 allows attackers to escalate privileges via a crafted exe...
CVE-2025-27997HIGH8.4An issue in Blizzard Battle.net v2.40.0.15267 allows attackers to escalate privileges via placing a crafted shell script...
CVE-2025-48416HIGH8.1An OpenSSH daemon listens on TCP port 22. There is a hard-coded entry in the "/etc/shadow" file in the firmware image fo...
CVE-2025-40775HIGH7.5When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it. If the TSIG conta...
CVE-2025-1416HIGH7In Proget MDM, a low-privileged user can retrieve passwords for managed devices and subsequently use functionalities res...
CVE-2025-4803HIGH7.2The Glossary by WPPedia – Best Glossary plugin for WordPress plugin for WordPress is vulnerable to PHP Object Injection ...
CVE-2025-48413HIGH7.7The `/etc/passwd` and `/etc/shadow` files reveal hard-coded password hashes for the operating system "root" user. The cr...
CVE-2025-1712HIGH8.8Argument injection in special agent configuration in Checkmk <2.4.0p1, <2.3.0p32, <2.2.0p42 and 2.1.0 allows authenticat...
CVE-2025-4998HIGH7.1A vulnerability has been found in H3C Magic R200G up to 100R002 and classified as problematic. Affected by this vulnerab...
CVE-2025-4997HIGH7.1A vulnerability, which was classified as problematic, was found in H3C R2+ProG up to 200R004. Affected is the function U...
CVE-2025-4364HIGH8.7The affected products could allow an unauthenticated attacker to access system information that could enable further acc...
CVE-2025-48391HIGH7.5In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API
CVE-2025-37991HIGH7.8In the Linux kernel, the following vulnerability has been resolved: parisc: Fix double SIGFPE crash Camm noticed that ...
CVE-2025-22157HIGH8.8This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 9.12.0, 10.3.0, 10.4.0, and...
CVE-2025-37981HIGH7.8In the Linux kernel, the following vulnerability has been resolved: scsi: smartpqi: Use is_kdump_kernel() to check for ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now