2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-62796MEDIUM5.8PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Versions 1.7.7 through 2.0.1 allow ...
CVE-2025-62794LOW3.8GitHub Workflow Updater is a VS Code extension that automatically pins GitHub Actions to specific commits for enhanced s...
CVE-2025-62727HIGH7.5Starlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthent...
CVE-2025-62368CRITICAL9Taiga is an open source project management platform. In versions 6.8.3 and earlier, a remote code execution vulnerabilit...
CVE-2025-61598MEDIUM5.3Discourse is an open source discussion platform. Version before 3.6.2 and 3.6.0.beta2, default Cache-Control response he...
CVE-2025-43017CRITICAL9.8HP ThinPro 8.1 System management application failed to verify user's true id. HP has released HP ThinPro 8.1 SP8, which ...
CVE-2025-11375MEDIUM6.5Consul and Consul Enterprise’s (“Consul”) event endpoint is vulnerable to denial of service (DoS) due to lack of maximum...
CVE-2025-11374MEDIUM6.5Consul and Consul Enterprise’s (“Consul”) key/value endpoint is vulnerable to denial of service (DoS) due to incorrect C...
CVE-2025-62367MEDIUM4.8Taiga is an open source project management platform. In versions 6.8.3 and earlier, Taiga API is vulnerable to time-base...
CVE-2025-61235CRITICAL9.1An issue was discovered in Dataphone A920 v2025.07.161103. A custom packet based on public documentation can be crafted,...
CVE-2025-59837HIGH7.2Astro is a web framework that includes an image proxy. In versions 5.13.4 and later before 5.13.10, the image proxy doma...
CVE-2025-27093MEDIUM6.3Sliver is a command and control framework that uses a custom Wireguard netstack. In versions 1.5.43 and earlier, and in ...
CVE-2025-40843HIGH7.8CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. ...
CVE-2025-12425HIGH7.8Local Privilege Escalation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
CVE-2025-12424CRITICAL9.8Privilege Escalation through SUID-bit Binary.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
CVE-2025-12423HIGH7.5Protocol manipulation might lead to denial of service.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19....
CVE-2025-61080MEDIUM5.4A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Clear2Pay Bank Visibility Application - Paym...
CVE-2025-60805HIGH7.5An issue was discovered in BESSystem BES Application Server thru 9.5.x allowing unauthorized attackers to gain sensitive...
CVE-2025-60800HIGH7.5Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to acce...
CVE-2025-60355CRITICAL9.8zhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
CVE-2025-60354HIGH7.5Unauthorized modification of arbitrary articles vulnerability exists in blog-vue-springboot.
CVE-2025-12422CRITICAL9.8Vulnerable Upgrade Feature (Arbitrary File Write) may lead to obtaining super user permissions on board.This issue affec...
CVE-2025-54605HIGH7.5Bitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 2 of 2).
CVE-2025-54604HIGH7.5Bitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 1 of 2).
CVE-2025-61155MEDIUM5.5The GameDriverX64.sys kernel-mode anti-cheat driver (v7.23.4.7 and earlier) contains an access control vulnerability in ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now