2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-3142HIGH8.8A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0. It has been rated as critical. This...
CVE-2025-3139HIGH7.8A vulnerability was found in code-projects Bus Reservation System 1.0 and classified as critical. Affected by this issue...
CVE-2025-3134HIGH8.8A vulnerability classified as critical has been found in code-projects Payroll Management System 1.0. This affects an un...
CVE-2025-3123HIGH7.2A vulnerability, which was classified as critical, has been found in WonderCMS 3.5.0. Affected by this issue is the func...
CVE-2025-31479HIGH8.2canonical/get-workflow-version-action is a GitHub composite action to get commit SHA that GitHub Actions reusable workfl...
CVE-2025-0257HIGH7.5HCL DevOps Deploy / HCL Launch could allow unauthorized access to other services or potential exposure of sensitive data...
CVE-2025-30080HIGH7.5Signalling in Pexip Infinity 29 through 36.2 before 37.0 has improper input validation that allows remote attackers to t...
CVE-2025-2704HIGH7.5OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of se...
CVE-2025-22925HIGH7.5OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the table parameter at /attendanc...
CVE-2025-22924HIGH8.8OS4ED openSIS v7.0 through v9.1 contains a SQL injection vulnerability via the stu_id parameter at /modules/students/Stu...
CVE-2025-22923HIGH8.8An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sendin...
CVE-2025-31285HIGH7.2A broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allow...
CVE-2025-31284HIGH7.2A broken access control vulnerability previously discovered in the Trend Vision One Status component could have allowed ...
CVE-2025-31283HIGH7.2A broken access control vulnerability previously discovered in the Trend Vision One User Roles component could have allo...
CVE-2025-31282HIGH7.2A broken access control vulnerability previously discovered in the Trend Vision One User Account component could have al...
CVE-2025-20212HIGH7.7A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series devices could allow an a...
CVE-2025-20139HIGH7.5A vulnerability in chat messaging features of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remo...
CVE-2025-0014HIGH7.3Incorrect default permissions on the AMD Ryzen(TM) AI installation folder could allow an attacker to achieve privilege e...
CVE-2025-0154HIGH7.5IBM TXSeries for Multiplatforms 9.1 and 11.1 could disclose sensitive information to a remote attacker due to improper n...
CVE-2025-31722HIGH8.8In Jenkins Templating Engine Plugin 2.5.3 and earlier, libraries defined in folders are not subject to sandbox protectio...
CVE-2025-30090HIGH7.2mime.php in SquirrelMail through 1.4.23-svn-20250401 and 1.5.x through 1.5.2-svn-20250401 allows XSS via e-mail headers,...
CVE-2025-27556HIGH7.5An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As ...
CVE-2025-21993HIGH7.1In the Linux kernel, the following vulnerability has been resolved: iscsi_ibft: Fix UBSAN shift-out-of-bounds warning i...
CVE-2025-21991HIGH7.8In the Linux kernel, the following vulnerability has been resolved: x86/microcode/AMD: Fix out-of-bounds on systems wit...
CVE-2025-3063HIGH8.8The Shopper Approved Reviews plugin for WordPress is vulnerable to unauthorized modification of data that can lead to pr...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now