2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-54562MEDIUM4.3A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows ...
CVE-2025-54561MEDIUM4.3An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.1...
CVE-2025-54560LOW3.8A Server-side Request Forgery vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0...
CVE-2025-54559LOW3.7An issue was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows remote ...
CVE-2025-54348MEDIUM6.5A Stored Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert version...
CVE-2025-54346HIGH7.6A Reflected Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert vers...
CVE-2025-54345HIGH7.5An issue was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. Sensitive Informati...
CVE-2025-54343CRITICAL9.6An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.1...
CVE-2025-54342LOW3.3A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There is Exp...
CVE-2025-54340MEDIUM4.1A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There is a B...
CVE-2025-54339CRITICAL10An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.1...
CVE-2025-4618MEDIUM4.4A sensitive information disclosure vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated no...
CVE-2025-4617LOW1.1An insufficient policy enforcement vulnerability in Palo Alto Networks Prisma® Browser on Windows allows a locally authe...
CVE-2025-4616LOW1.1An insufficient validation of an untrusted input vulnerability in Palo Alto Networks Prisma® Browser allows a locally au...
CVE-2025-13172HIGH8.8A security flaw has been discovered in CodeAstro Gym Management System 1.0. Affected is an unknown function of the file ...
CVE-2025-13171HIGH8.8A vulnerability was identified in ZZCMS 2023. This impacts an unknown function of the file /admin/wangkan_list.php. Such...
CVE-2025-13204HIGH7.3npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use ...
CVE-2025-12897Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2025-8870MEDIUM5.6On affected platforms running Arista EOS, certain serial console input might result in an unexpected reload of the devic...
CVE-2025-64446CRITICAL9.8A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb...
CVE-2025-13170CRITICAL9.8A vulnerability was detected in code-projects Simple Online Hotel Reservation System 1.0. This issue affects some unknow...
CVE-2025-13169CRITICAL9.8A security vulnerability has been detected in code-projects Simple Online Hotel Reservation System 1.0. This vulnerabili...
CVE-2025-13168CRITICAL9.8A weakness has been identified in ury-erp ury up to 0.2.0. This affects the function overrided_past_order_list of the fi...
CVE-2025-9982HIGH7.5A vulnerability exists in QuickCMS version 6.8 where sensitive admin credentials are hardcoded in a configuration file a...
CVE-2025-12149MEDIUM6In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, whe...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now