2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-20378MEDIUM6.1In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, 9.2.9, and Splunk Cloud Platform versions below 10.0.2503.5, 9...
CVE-2025-63419MEDIUM6.1Cross Site Scripting (XSS) vulnerability in CrushFTP 11.3.6_48. The Web-Based Server has a feature where users can share...
CVE-2025-59491MEDIUM6.1Cross Site Scripting vulnerability in CentralSquare Community Development 19.5.7 via form fields.
CVE-2025-59089MEDIUM5.9If an attacker causes kdcproxy to connect to an attacker-controlled KDC server (e.g. through server-side request forgery...
CVE-2025-59088HIGH8.6If kdcproxy receives a request for a realm which does not have server addresses defined in its configuration, by default...
CVE-2025-52331MEDIUM6.1Cross-site scripting (XSS) vulnerability in the generate report functionality in Rarlab WinRAR 7.11, allows attackers to...
CVE-2025-2843HIGH8.8A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment...
CVE-2025-13042HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.166 allowed a remote attacker to potentially exp...
CVE-2025-11797HIGH7.8A maliciously crafted DWG file, when parsed through Autodesk 3ds Max, can force a Use-After-Free vulnerability. A malici...
CVE-2025-11795HIGH7.8A maliciously crafted JPG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A ...
CVE-2025-9316MEDIUM6.9N-central < 2025.4 can generate sessionIDs for unauthenticated users This issue affects N-central: before 2025.4.
CVE-2025-64293HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Golemiq 0 Day Anal...
CVE-2025-64281CRITICAL9.8An Authentication Bypass issue in CentralSquare Community Development 19.5.7 allows attackers to access the admin panel ...
CVE-2025-64280CRITICAL9.8A SQL Injection Vulnerability in CentralSquare Community Development 19.5.7 allows attackers to inject SQL via the permi...
CVE-2025-63353CRITICAL9.8A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-s...
CVE-2025-63289CRITICAL9.1Sogexia Android App Compile Affected SDK v35, Max SDK 32 and fixed in v36, was discovered to contain hardcoded encryptio...
CVE-2025-12152Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2025-12068Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2025-11700HIGH7.5N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure
CVE-2025-11367CRITICAL9.8The N-central Software Probe < 2025.4 is vulnerable to Remote Code Execution via deserialization
CVE-2025-11366CRITICAL9.8N-central < 2025.4 is vulnerable to authentication bypass via path traversal
CVE-2025-63667HIGH7.5Incorrect access control in SIMICAM v1.16.41-20250725, KEVIEW v1.14.92-20241120, ASECAM v1.14.10-20240725 allows attacke...
CVE-2025-63666CRITICAL9.8Tenda AC15 v15.03.05.18_multi) issues an authentication cookie that exposes the account password hash to the client and ...
CVE-2025-11567HIGH7.3CWE-276: Incorrect Default Permissions vulnerability exists that could cause elevated system access when the target inst...
CVE-2025-11566MEDIUM6.9CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker on ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now