2025 CVE Vulnerabilities

45,208 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-59503CRITICAL9.8Server-side request forgery (ssrf) in Azure Compute Gallery allows an unauthorized attacker to elevate privileges over a...
CVE-2025-59500HIGH8.8Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network...
CVE-2025-59273CRITICAL9.8Improper access control in Azure Event Grid allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-58456HIGH8.2A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerab...
CVE-2025-58078HIGH8.3A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnera...
CVE-2025-12100HIGH8.8Incorrect Default Permissions vulnerability in MongoDB BI Connector ODBC driver allows Privilege Escalation.This issue a...
CVE-2025-62517MEDIUM5.9Rollbar.js offers error tracking and logging from Javascript to Rollbar. In versions before 2.26.5 and from 3.0.0-alpha1...
CVE-2025-62236MEDIUM6.9The Frontier Airlines website has a publicly available endpoint that validates if an email addresses is associated with ...
CVE-2025-58428CRITICAL9.9The TLS4B ATG system's SOAP-based interface is vulnerable due to its accessibility through the web services handler. Thi...
CVE-2025-57848MEDIUM6.4A container privilege escalation flaw was found in certain Container-native Virtualization images. This issue stems from...
CVE-2025-55067HIGH7.1The TLS4B ATG system is vulnerable to improper handling of Unix time values that exceed the 2038 epoch rollover. When th...
CVE-2025-54966MEDIUM4.3An issue was discovered in BAE SOCET GXP before 4.6.0.2. Some endpoints on the SOCET GXP Job Status Service may return s...
CVE-2025-54964HIGH8.4An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Servi...
CVE-2025-54963MEDIUM6.5An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Servi...
CVE-2025-12044HIGH7.5Vault and Vault Enterprise (“Vault”) are vulnerable to an unauthenticated denial of service when processing JSON payload...
CVE-2025-6980HIGH7.5Captive Portal can expose sensitive information
CVE-2025-6979HIGH8.8Captive Portal can allow authentication bypass
CVE-2025-6978HIGH7.2Diagnostics command injection vulnerability
CVE-2025-62255MEDIUM6.1Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page in Liferay Portal 7.4.0 through 7....
CVE-2025-60859MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Gnuboard 5.6.15 allows authenticated attackers to execute arbitrary code via...
CVE-2025-60837MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in ...
CVE-2025-54808HIGH7.8Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 stores authentication tokens in a file locat...
CVE-2025-23352HIGH7.8NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause uninitiali...
CVE-2025-23347HIGH7.8NVIDIA Project G-Assist contains a vulnerability where an attacker might be able to escalate permissions. A successful e...
CVE-2025-23345MEDIUM4.4NVIDIA Display Driver for Windows and Linux contains a vulnerability in a video decoder, where an attacker might cause a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now