2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-3922MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.4 before 18.9.6, 18.10 before 18.10.4, and...
CVE-2025-0186MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.9.6, 18.10 before 18.10.4, and...
CVE-2025-58922MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada allows Cross Site Request Forgery.This issue affect...
CVE-2025-70420——Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2025-41029CRITICAL9.3SQL injection vulnerability in Zeon Academy Pro by Zeon Global Tech. This vulnerability allows an attacker to retrieve, ...
CVE-2025-41011MEDIUM6.1HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the vic...
CVE-2025-15638CRITICAL10Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt. Net::Dropbear versions before...
CVE-2025-31981MEDIUM5.3HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, al...
CVE-2025-31958HIGH8.2HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise wh...
CVE-2025-1241MEDIUM4.9Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize...
CVE-2025-14362HIGH7.3The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attemptin...
CVE-2025-10354MEDIUM5.1Cross-Site Scripting (XSS) vulnerability reflected in Semantic MediaWiki. This vulnerability allows an attacker to execu...
CVE-2025-13826HIGH8.2Zervit's portable HTTP/web server is vulnerable to remote DoS attacks when a configuration reset request is made. The vu...
CVE-2025-11249——Rejected reason: This CVE id was assigned as a duplicate of CVE-2025-66414.
CVE-2025-66954MEDIUM6.5A vulnerability exists in the Buffalo Link Station version 1.85-0.01 that allows unauthenticated or guest-level users to...
CVE-2025-66335MEDIUM5.3Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context han...
CVE-2025-13480MEDIUM6.5Fudo Enterprise in versions from 5.5.0 through 5.6.2 allows low privileged users to access certain administrator-only re...
CVE-2025-65104HIGH7.5Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect...
CVE-2025-70795MEDIUM5.5STProcessMonitor 11.11.4.0, part of the Safetica Application suite, allows an admin-privileged user to send crafted IOCT...
CVE-2025-46641MEDIUM6.6Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont...
CVE-2025-46607HIGH7.2Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont...
CVE-2025-46606HIGH7.2Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont...
CVE-2025-46605HIGH7.2Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont...
CVE-2025-36568HIGH7.8Dell PowerProtect Data Domain BoostFS for client of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release versio...
CVE-2025-15625CRITICAL9.8Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now