2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-64689Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it relates to interna...
CVE-2025-64688Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it relates to interna...
CVE-2025-64687Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it was fixed before p...
CVE-2025-64686Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it was fixed before p...
CVE-2025-64685HIGH7.5In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure
CVE-2025-64684HIGH7.5In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form
CVE-2025-64683HIGH7.5In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API
CVE-2025-64682LOW3.7In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit
CVE-2025-64681LOW3.7In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations
CVE-2025-64457HIGH7In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition
CVE-2025-64456HIGH7.8In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation
CVE-2025-12939CRITICAL9.8A security flaw has been discovered in SourceCodester Interview Management System up to 1.0. Affected by this issue is s...
CVE-2025-12938CRITICAL9.8A vulnerability was identified in projectworlds Online Admission System 1.0. Affected by this vulnerability is an unknow...
CVE-2025-41001MEDIUM5.4Cross Site Scripting (XSS) vulnerability stored in SOPlanning v1.53.02, which consist of a stored XSS due to a lack of p...
CVE-2025-12405HIGH7.7An improper privilege management vulnerability was found in Looker Studio. It impacted all JDBC-based connectors. A Loo...
CVE-2025-41107MEDIUM5.4Stored Cross Site Scripting (XSS) vulnerability in Smart School 7.0 due to lack of proper validation of user input when ...
CVE-2025-12409HIGH7.3A SQL injection vulnerability was discovered in Looker Studio that allowed for data exfiltration from BigQuery data sour...
CVE-2025-12397HIGH7.6A SQL injection vulnerability was found in Looker Studio. A Looker Studio user with report view access could inject mal...
CVE-2025-12155HIGH7.1A Command Injection vulnerability, resulting from improper file path sanitization (Directory Traversal) in Looker allows...
CVE-2025-41731HIGH7.4A vulnerability was identified in the password generation algorithm when accessing the debug-interface. An unauthenticat...
CVE-2025-12933CRITICAL9.8A vulnerability was identified in SourceCodester Baby Care System 1.0. This affects an unknown part of the file /updatew...
CVE-2025-62689HIGH8.7NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in co...
CVE-2025-59777HIGH8.7NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in co...
CVE-2025-12932CRITICAL9.8A vulnerability was determined in SourceCodester Baby Care System 1.0. Affected by this issue is some unknown functional...
CVE-2025-12931CRITICAL9.8A vulnerability was found in SourceCodester Food Ordering System 1.0. Affected by this vulnerability is an unknown funct...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now