2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-64389HIGH8.3The web server of the device performs exchanges of sensitive information in clear text through an insecure protocol.
CVE-2025-64388CRITICAL9.2Denial of service of the web server through specific requests to this protocol
CVE-2025-64387MEDIUM5.1The web application is vulnerable to a so-called ‘clickjacking’ attack. In this type of attack, the vulnerable page is i...
CVE-2025-64385CRITICAL9.2The equipment initially can be configured using the manufacturer's application, by Wi-Fi, by the web server or with the ...
CVE-2025-64168HIGH7.1Agno is a multi-agent framework, runtime and control plane. From 2.0.0 to before 2.2.2, under high concurrency, when ses...
CVE-2025-61427MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in BEO GmbH BEO Atlas Einfuhr Ausfuhr 3.0 allows attackers to execu...
CVE-2025-60749HIGH7.8DLL Hijacking vulnerability in Trimble SketchUp desktop 2025 via crafted libcef.dll used by sketchup_webhelper.exe.
CVE-2025-57108CRITICAL9.8Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader....
CVE-2025-57107HIGH7.1Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader...
CVE-2025-57106HIGH7.5Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerabi...
CVE-2025-12501HIGH7.5Integer overflow in GameMaker IDE below 2024.14.0 version can lead to can lead to application crashes through denial-of-...
CVE-2025-64386HIGH7.7The equipment grants a JWT token for each connection in the timeline, but during an active valid session, a hijacking of...
CVE-2025-12521MEDIUM5.3The Analytify Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ...
CVE-2025-12460MEDIUM5.3An XSS issue was discovered in Afterlogic Aurora webmail version 9.8.3 and below. An attacker can send a specially craft...
CVE-2025-4952MEDIUM6.8Tampering of the registry entries might have led to preventing the ESET security products from starting correctly on the...
CVE-2025-36249MEDIUM5.3IBM Jazz for Service Management 1.1.3.0 through 1.1.3.25 does not set the secure attribute on authorization tokens or se...
CVE-2025-33003HIGH7.8IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a non-root user to gain higher privileges/capabi...
CVE-2025-64368MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Mikado-Themes Bard bardwp allows Cross Site Request Forgery.This issu...
CVE-2025-64367MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adrian Tobey Groun...
CVE-2025-64366HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStu...
CVE-2025-64365MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in colabrio Ohio Extr...
CVE-2025-64364HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-64363HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-64362MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SeventhQueen K Ele...
CVE-2025-64361MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StylemixThemes Con...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now