2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13302CRITICAL9.8A vulnerability was identified in code-projects Courier Management System 1.0. This affects an unknown part of the file ...
CVE-2025-36118HIGH7.5IBM Storage Virtualize 8.4, 8.5, 8.7, and 9.1 IKEv1 implementation allows remote attackers to obtain sensitive informati...
CVE-2025-13301CRITICAL9.8A vulnerability was found in itsourcecode Web-Based Internet Laboratory Management System 1.0. Affected by this vulnerab...
CVE-2025-13300CRITICAL9.8A vulnerability has been found in itsourcecode Web-Based Internet Laboratory Management System 1.0. Affected is an unkno...
CVE-2025-36357HIGH8IBM Planning Analytics Local 2.1.0 through 2.1.14 could allow a remote authenticated user to traverse directories on the...
CVE-2025-36299MEDIUM4.3IBM Planning Analytics Local 2.1.0 through 2.1.14 stores sensitive information in source code could be used in further a...
CVE-2025-13299CRITICAL9.8A flaw has been found in itsourcecode Web-Based Internet Laboratory Management System 1.0. This impacts an unknown funct...
CVE-2025-13298CRITICAL9.8A vulnerability was detected in itsourcecode Web-Based Internet Laboratory Management System 1.0. This affects an unknow...
CVE-2025-63292LOW3.5Freebox v5 HD (firmware = 1.7.20), Freebox v5 Crystal (firmware = 1.7.20), Freebox v6 Révolution r1–r3 (firmware = 4.7.x...
CVE-2025-13216Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2025-64758MEDIUM4.8@dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis...
CVE-2025-64756HIGH7.5Glob matches files using patterns the shell uses. Starting in version 10.2.0 and prior to versions 10.5.0 and 11.1.0, th...
CVE-2025-64342MEDIUM6.9ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. When the ESP32 is in advertising mode, if it re...
CVE-2025-58407HIGH7.4Kernel or driver software installed on a Guest VM may post improper commands to the GPU Firmware to exploit a TOCTOU rac...
CVE-2025-55059MEDIUM6.1CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
CVE-2025-55058CRITICAL9.8CWE-20 Improper Input Validation
CVE-2025-55057HIGH8.8Multiple CWE-352 Cross-Site Request Forgery (CSRF)
CVE-2025-55056MEDIUM6.1Multiple CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
CVE-2025-55055CRITICAL9.8CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-34323HIGH7.8Nagios Log Server versions prior to 2026R1.0.1 are vulnerable to local privilege escalation due to a combination of sudo...
CVE-2025-34322HIGH7.2Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability in the experimen...
CVE-2025-13297CRITICAL9.8A security vulnerability has been detected in itsourcecode Web-Based Internet Laboratory Management System 1.0. The impa...
CVE-2025-63918MEDIUM6.2PDFPatcher executable does not validate user-supplied file paths, allowing directory traversal attacks allowing attacker...
CVE-2025-63917HIGH7.1PDFPatcher thru 1.1.3.4663 executable's XML bookmark import functionality does not restrict XML external entity (XXE) re...
CVE-2025-62519HIGH7.2phpMyFAQ is an open source FAQ web application. Prior to version 4.0.14, an authenticated SQL injection vulnerability in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now