2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-62788HIGH7.5Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, w_copy_ev...
CVE-2025-62787HIGH7.5Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.10.2, a buffer ...
CVE-2025-61234HIGH7.5Incorrect access control on Dataphone A920 v2025.07.161103 exposes a service on port 8888 by default on the local networ...
CVE-2025-60595HIGH8.2SPH Engineering UgCS 5.13.0 is vulnerable to Arbitary code execution.
CVE-2025-56558LOW3The Dyson MQTT server (2022 and possibly later) allows publications and subscriptions by a client that has the correct v...
CVE-2025-1549MEDIUM6.3A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user ...
CVE-2025-12479HIGH8.8Systemic Lack of Cross-Site Request Forgery (CSRF) Token Implementation.This issue affects BLU-IC2: through 1.19.5; BLU-...
CVE-2025-12478CRITICAL9.8Non-Compliant TLS Configuration.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
CVE-2025-12477CRITICAL9.8Server Version Disclosure.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
CVE-2025-12476CRITICAL9.8Resource Lacking AuthN.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
CVE-2025-62786HIGH8.1Wazuh is a free and open source platform used for threat prevention, detection, and response. A heap-based out-of-bounds...
CVE-2025-62785HIGH7.5Wazuh is a free and open source platform used for threat prevention, detection, and response. fillData() implementation ...
CVE-2025-60898MEDIUM5.8An unauthenticated server-side request forgery (SSRF) vulnerability in the Thumbnail via-uri endpoint of Halo CMS 2.21 a...
CVE-2025-60542MEDIUM6.5SQL Injection vulnerability in TypeORM before 0.3.26 via crafted request to repository.save or repository.update due to ...
CVE-2025-54384MEDIUM6.3CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.9 and 2.11.4,...
CVE-2025-12148MEDIUM6In Search Guard versions 3.1.1 and earlier, Field Masking (FM) rules are improperly enforced on fields of type IP (IP Ad...
CVE-2025-12147MEDIUM6In Search Guard FLX versions 3.1.1 and earlier, Field-Level Security (FLS) rules are improperly enforced on object-value...
CVE-2025-63622CRITICAL9.8A vulnerability was found in code-projects Online Complaint Site 1.0. This issue affects some unknown processing of the ...
CVE-2025-61429HIGH8.8An issue in NCR Atleos Terminal Manager (ConfigApp) v3.4.0 allows attackers to escalate privileges via a crafted request...
CVE-2025-61156HIGH7.8Incorrect access control in the kernel driver of ThreatFire System Monitor v4.7.0.53 allows attackers to escalate privil...
CVE-2025-10932HIGH8.2Uncontrolled Resource Consumption vulnerability in Progress MOVEit Transfer (AS2 module).This issue affects MOVEit Trans...
CVE-2025-64150MEDIUM5.4A missing permission check in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers with Overall/Read per...
CVE-2025-64149MEDIUM5.4A cross-site request forgery (CSRF) vulnerability in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attacker...
CVE-2025-64148MEDIUM4.3A missing permission check in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers with Overall/Read per...
CVE-2025-64147MEDIUM4.3Jenkins Curseforge Publisher Plugin 1.0 does not mask API Keys displayed on the job configuration form, increasing the p...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now