2025 CVE Vulnerabilities

45,199 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-32986HIGH7.5NETSCOUT nGeniusONE before 6.4.0 b2350 has a Sensitive File Accessible Without Proper Authentication to an endpoint.
CVE-2025-32983HIGH7.5NETSCOUT nGeniusONE before 6.4.0 b2350 allows Technical Information Disclosure via a Stack Trace.
CVE-2025-32982HIGH7.5NETSCOUT nGeniusONE before 6.4.0 b2350 has a Broken Authorization Schema for the report module.
CVE-2025-32981HIGH7.1NETSCOUT nGeniusONE before 6.4.0 b2350 allows local users to leverage Insecure Permissions for the nGeniusCLI File.
CVE-2025-28128HIGH7An issue in Mytel Telecom Online Account System v1.0 allows attackers to bypass the OTP verification process via a craft...
CVE-2025-3935HIGH7.2ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web ...
CVE-2025-3928HIGH8.8Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. Accordi...
CVE-2025-43862HIGH7.6Dify is an open-source LLM app development platform. Prior to version 0.6.12, a normal user is able to access and modify...
CVE-2025-43016HIGH7.5In JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug session
CVE-2025-3642HIGH8.8A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default...
CVE-2025-3641HIGH8.8A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default...
CVE-2025-3638HIGH8.8A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to pr...
CVE-2025-3625HIGH7.1A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about s...
CVE-2025-32044HIGH7.5A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—i...
CVE-2025-1565HIGH7.5The Mayosis Core plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.4.1 v...
CVE-2025-1279HIGH8.8The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privileg...
CVE-2025-46617HIGH7.2Quantum StorNext Web GUI API before 7.2.4 grants access to internal StorNext configuration and unauthorized modification...
CVE-2025-2238HIGH8.8The Vikinger theme for WordPress is vulnerable to privilege in all versions up to, and including, 1.9.30. This is due to...
CVE-2025-46613HIGH7.5OpenPLC 3 through 64f9c11 has server.cpp Memory Corruption because a thread may access handleConnections arguments after...
CVE-2025-3511HIGH7.5Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remot...
CVE-2025-46546HIGH8.8In Sherpa Orchestrator 141851, multiple time-based blind SQL injections can be performed by an authenticated user. This ...
CVE-2025-43865HIGH8.2React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, it's possible to modify pre-re...
CVE-2025-43864HIGH7.5React Router is a router for React. Starting in version 7.2.0 and prior to version 7.5.2, it is possible to force an app...
CVE-2025-3606HIGH8.7Vestel AC Charger version 3.75.0 contains a vulnerability that could enable an attacker to access files containing s...
CVE-2025-2185HIGH8.5ALBEDO Telecom Net.Time - PTP/NTP clock (Serial No. NBC0081P) software release 1.4.4 is vulnerable to an insufficient se...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now