2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-52347HIGH7.8An issue in the component DirectIo64.sys of PassMark BurnInTest v11.0 Build 1011, OSForensics v11.1 Build 1007, and Perf...
CVE-2025-69606MEDIUM6.1Cross-Site Scripting (XSS) vulnerability was discovered in the GSVoIP web panel version 2.0.90. The `msg` parameter in t...
CVE-2025-63548HIGH7.5An issue in Eprosima Micro-XREC-DDS Agent v.3.0.1 allows a remote attacker to cause a denial of service via a packet spe...
CVE-2025-63547HIGH7.5An issue in Eprosima Micro-XREC-DDS Agent v.3.0.1 allows a remote attacker to cause a denial of service via a crafted pa...
CVE-2025-36335MEDIUM5.5IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1 stores user credentials in plain text which can be read by a lo...
CVE-2025-36180HIGH7.5IBM watsonx.data 2.2 through 2.3 IBM Lakehouse does not properly restrict communication between pods which could allow a...
CVE-2025-36122MEDIUM6.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could...
CVE-2025-14688MEDIUM5.3IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could...
CVE-2025-56568HIGH7.5Assertion failure vulnerability in the PCO (Protocol Configuration Options) parser in the SMF (Session Management Functi...
CVE-2025-46115HIGH7.5An issue in open5gs v.2.7.3 allows a remote attacker to cause a denial of service via a crafted PDU Session Modification...
CVE-2025-71284CRITICAL9.8Synway SMG Gateway Management Software contains an OS command injection vulnerability in the RADIUS configuration endpoi...
CVE-2025-51846HIGH8.7CryptPad 2025.3.1 allows unbounded WebSocket frame flood. A remote, unauthenticated attacker can significantly degrade o...
CVE-2025-51850——Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2025-51849——Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2025-51847——Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2025-14543CRITICAL9.1Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows ...
CVE-2025-13890——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-12494. Reason: This candidate is a ...
CVE-2025-14576HIGH7.8Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicio...
CVE-2025-13030CRITICAL9.8All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image ...
CVE-2025-50328HIGH7.3A vulnerability in B1 Free Archiver v1.5.86 allows files extracted from downloaded archives to bypass Windows Mark of th...
CVE-2025-56537MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 and fixed in v.7.0 allows attackers to execute...
CVE-2025-56536MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scri...
CVE-2025-56535MEDIUM6.1A cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or ...
CVE-2025-56534MEDIUM6.1A cross-site scripting (XSS) vulnerability in the custom authenticator driver of opennebula v6.10.0.1 allows attackers t...
CVE-2025-10503MEDIUM6.1The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now