2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-31489HIGH8.7MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. The signature componen...
CVE-2025-31485HIGH7.5API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Prior to 4.0.22 and 3.4.17, a GraphQL g...
CVE-2025-31481HIGH7.5API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Using the Relay special node type you c...
CVE-2025-31119HIGH7.6generator-jhipster-entity-audit is a JHipster module to enable entity audit and audit log page. Prior to 5.9.1, generato...
CVE-2025-29570HIGH7.8An issue in Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 allows a local attacker to escalate privileges via t...
CVE-2025-29504HIGH7.8Insecure Permission vulnerability in student-manage 1 allows a local attacker to escalate privileges via the Unsafe perm...
CVE-2025-31487HIGH7.7The XWiki JIRA extension provides various integration points between XWiki and JIRA (macros, UI, CKEditor plugin). If th...
CVE-2025-3167HIGH7.5A vulnerability, which was classified as problematic, has been found in Tenda AC23 16.03.07.52. This issue affects some ...
CVE-2025-3166HIGH7.8A vulnerability classified as critical was found in code-projects Product Management System 1.0. This vulnerability affe...
CVE-2025-31115HIGH8.7XZ Utils provide a general-purpose data-compression library plus command-line tools. In XZ Utils 5.3.3alpha to 5.8.0, th...
CVE-2025-3163HIGH7.8A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been declared as critical. Affected by this vulnerabi...
CVE-2025-29987HIGH8.8Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficie...
CVE-2025-3162HIGH7.8A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been classified as critical. Affected is the function...
CVE-2025-3161HIGH8.8A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. This issue affects the function Shutdown...
CVE-2025-0272HIGH7.6HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary H...
CVE-2025-3159HIGH7.8A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the...
CVE-2025-3158HIGH7.8A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. Affected by...
CVE-2025-3155HIGH7.4A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vu...
CVE-2025-32049HIGH7.5A flaw was found in libsoup. The SoupWebsocketConnection may accept a large WebSocket message, which may cause libsoup t...
CVE-2025-31909HIGH7.5Missing Authorization vulnerability in Apptivo Apptivo Business Site CRM apptivo-business-site allows Exploiting Incorre...
CVE-2025-31907HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Labib Ahmed Team B...
CVE-2025-31905HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark O'Donnell Tea...
CVE-2025-31903HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xavi Ivars XV Rand...
CVE-2025-31902HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reputeinfosystems ...
CVE-2025-31901HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digihood Digihood ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now