2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-59716MEDIUM5.3ownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endp...
CVE-2025-57244MEDIUM5.4OpenKM Community Edition 6.3.12 is vulnerable to stored cross-site scripting (XSS) in the user account creation interfac...
CVE-2025-46424MEDIUM4.4Dell CloudLink, versions prior to 8.2, contain use of a Cryptographic Primitive with a Risky Implementation vulnerabilit...
CVE-2025-46366MEDIUM6.7Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user may exploit and gain parallel p...
CVE-2025-46365MEDIUM6.7Dell CloudLink, versions prior 8.1.1, contain a Command Injection vulnerability which can be exploited by an Authenticat...
CVE-2025-46364HIGH7.2Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user with known password can run CLI...
CVE-2025-45379HIGH8.4Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run comma...
CVE-2025-45378CRITICAL9.1Dell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell. A Privileged user with known pass...
CVE-2025-43990HIGH7.8Dell Command Monitor (DCM), versions prior to 10.12.3.28, contains an Execution with Unnecessary Privileges vulnerabilit...
CVE-2025-30479HIGH7.2Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run comma...
CVE-2025-20377MEDIUM4.3A vulnerability in the API subsystem of Cisco Unified Intelligence Center could allow an authenticated, remote attacker ...
CVE-2025-20376HIGH7.2A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute a...
CVE-2025-20375HIGH7.2A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute a...
CVE-2025-20374MEDIUM4.9A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to perform a directory ...
CVE-2025-20358CRITICAL9.8A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticat...
CVE-2025-20354CRITICAL9.8A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, ...
CVE-2025-20343HIGH7.5A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures on Cisco Identity Servi...
CVE-2025-20305MEDIUM4.9A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obta...
CVE-2025-20304MEDIUM5.4Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticat...
CVE-2025-20303MEDIUM5.4Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticat...
CVE-2025-20289MEDIUM5.4Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticat...
CVE-2025-63601CRITICAL9.9Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to up...
CVE-2025-61304CRITICAL9.8OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address.
CVE-2025-60753MEDIUM5.5An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c whe...
CVE-2025-57130HIGH8.8An Incorrect Access Control vulnerability in the user management component of ZwiiCMS up to v13.6.07 allows a remote, au...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now