2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-62184LOW3.4Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interf...
CVE-2025-14213HIGH8.3Cato Networks’ Socket versions prior to 25 contain a command injection vulnerability that allows an authenticated attack...
CVE-2025-15618CRITICAL9.1Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret key. Business::Online...
CVE-2025-41357MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to...
CVE-2025-41356MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to...
CVE-2025-41355MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker t...
CVE-2025-10559CRITICAL9.1A Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DE...
CVE-2025-10553MEDIUM5.4A Stored Cross-site Scripting (XSS) vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manag...
CVE-2025-10551MEDIUM5.4A Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovat...
CVE-2025-32957HIGH7.2baserCMS is a website development framework. Prior to version 5.2.3, the application's restore function allows users to ...
CVE-2025-66215MEDIUM6.8OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to t...
CVE-2025-66038MEDIUM6.8OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a com...
CVE-2025-66037MEDIUM6.8OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_p...
CVE-2025-49010MEDIUM6.8OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to t...
CVE-2025-3716MEDIUM5.3User enumeration in ESET Protect (on-prem) via Response Timing.
CVE-2025-15379CRITICAL9.8A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_...
CVE-2025-15036CRITICAL10A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artif...
CVE-2025-7741LOW2.1Hardcoded Password Vulnerability have been found in CENTUM. Affected products contain a hardcoded password for the user ...
CVE-2025-15604CRITICAL9.8Amon2 versions before 6.17 for Perl use an insecure random_string implementation for security functions. In versions 6....
CVE-2025-9497CRITICAL9.8Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This...
CVE-2025-15445MEDIUM5.4The Restaurant Cafeteria WordPress theme through 0.4.6 exposes insecure admin-ajax actions without nonce or capability c...
CVE-2025-12886HIGH7.2The Oxygen Theme theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, ...
CVE-2025-15612HIGH8.1Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k...
CVE-2025-15617HIGH8.1Wazuh version 4.12.0 contains an exposure vulnerability in GitHub Actions workflow artifacts that allows attackers to ex...
CVE-2025-15616HIGH7.2Wazuh wazuh-agent and wazuh-manager versions 2.1.0 before 4.8.0 contain multiple shell injection and untrusted search pa...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now