2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-46428HIGH8.8Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used...
CVE-2025-46427HIGH8.8Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used ...
CVE-2025-27368MEDIUM4.3IBM OpenPages 9.0 and 9.1 is vulnerable to information disclosure of sensitive information due to a weaker than expected...
CVE-2025-13060CRITICAL9.8A security vulnerability has been detected in SourceCodester Survey Application System 1.0. This affects an unknown func...
CVE-2025-13059CRITICAL9.8A weakness has been identified in SourceCodester Alumni Management System 1.0. The impacted element is an unknown functi...
CVE-2025-13058MEDIUM5.4A security flaw has been discovered in soerennb eXtplorer up to 2.1.15. The affected element is an unknown function of t...
CVE-2025-12048HIGH7.7An arbitrary file upload vulnerability was reported in the Lenovo Scanner Pro client during an internal security assessm...
CVE-2025-12047MEDIUM6A vulnerability was reported in the Lenovo Scanner pro application during an internal security assessment that, under ce...
CVE-2025-10495HIGH7.7A potential vulnerability was reported in the Lenovo PC Manager, Lenovo App Store, Lenovo Browser, and Lenovo Legion Zon...
CVE-2025-64099HIGH8.1Open Access Management (OpenAM) is an access management solution. In versions prior to 16.0.0, if the "claims_parameter_...
CVE-2025-63929HIGH7.5A null pointer dereference vulnerability exists in airpig2011 IEC104 thru Commit be6d841 (2019-07-08). When multiple thr...
CVE-2025-63927MEDIUM4A heap-use-after-free vulnerability exists in airpig2011 IEC104 thru Commit be6d841 (2019-07-08). During multi-threaded ...
CVE-2025-63679HIGH7.5free5gc v4.1.0 and before is vulnerable to Buffer Overflow. When AMF receives an UplinkRANConfigurationTransfer NGAP mes...
CVE-2025-61667HIGH7The Datadog Agent collects events and metrics from hosts and sends them to Datadog. A vulnerability within the Datadog L...
CVE-2025-60646MEDIUM6.1A stored cross-site scripting (XSS) in the Business Line Management module of Xxl-api v1.3.0 attackers to execute arbitr...
CVE-2025-57812LOW3.7CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the for...
CVE-2025-57310HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability in Salmen2/Simple-Faucet-Script v1.07 via crafted POST request to admi...
CVE-2025-56385CRITICAL9.8A SQL injection vulnerability exists in the login functionality of WellSky Harmony version 4.1.0.2.83 within the 'xmHarm...
CVE-2025-13057CRITICAL9.8A vulnerability was identified in Campcodes School Fees Payment Management System 1.0. Impacted is an unknown function o...
CVE-2025-65002HIGH7.5Fujitsu / Fsas Technologies iRMC S6 on M5 before 1.37S mishandles Redfish/WebUI access if the length of a username is ex...
CVE-2025-65001HIGH8.2Fujitsu fbiosdrv.sys before 2.5.0.0 allows an attacker to potentially affect system confidentiality, integrity, and avai...
CVE-2025-63811HIGH7.5An issue was discovered in dvsekhvalnov jose2go 1.5.0 thru 1.7.0 allowing an attacker to cause a Denial-of-Service (DoS)...
CVE-2025-60645MEDIUM6.5A Cross-Site Request Forgery (CSRF) in xxl-api v1.3.0 allows attackers to arbitrarily add users to the management module...
CVE-2025-25236MEDIUM5.3Omnissa Workspace ONE UEM contains an observable response discrepancy vulnerability. A malicious actor may be able to en...
CVE-2025-20379LOW3.5In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, and 9.2.9 and Splunk Cloud Platform versions below 9.3.2411.11...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now