2025 CVE Vulnerabilities

45,209 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-10914HIGH7.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Soft...
CVE-2025-10727MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ArkSigner S...
CVE-2025-62499MEDIUM4.8Movable Type contains a stored cross-site scripting vulnerability in Edit CategorySet of ContentType page. If crafted in...
CVE-2025-61865HIGH8.4Multiple NAS management applications provided by I-O DATA DEVICE, INC. register Windows services with unquoted file path...
CVE-2025-54856MEDIUM4.8Movable Type contains a stored cross-site scripting vulnerability in Edit ContentData page. If crafted input is stored b...
CVE-2025-54806MEDIUM6.1GROWI v4.2.7 and earlier contains a cross-site scripting vulnerability in the page alert function. If a user accesses a...
CVE-2025-62820MEDIUM4.9Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within t...
CVE-2025-62813Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2025-48430MEDIUM5.5Uncaught Exception (CWE-248) in the Command Centre Server allows an Authorized and Privileged Operator to crash the Comm...
CVE-2025-48428MEDIUM6.7Cleartext Storage of Sensitive Information (CWE-312) in the Gallagher Morpho integration could allow an authenticated us...
CVE-2025-47699CRITICAL9.9Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) in the Gallagher Morpho integration...
CVE-2025-41402MEDIUM5.5Client-Side Enforcement of Server-Side Security (CWE-602) in the Command Centre Server allows a privileged operator to e...
CVE-2025-35981MEDIUM5.5Exposure of Private Personal Information to an Unauthorized Actor (CWE-359) in the Command Centre Server allows a privil...
CVE-2025-12104CRITICAL9.8Outdated and Vulnerable UI Dependencies might potentially lead to exploitation.This issue affects BLU-IC2: through 1.19....
CVE-2025-62812Rejected reason: Not used
CVE-2025-62811Rejected reason: Not used
CVE-2025-62810Rejected reason: Not used
CVE-2025-62809Rejected reason: Not used
CVE-2025-62808Rejected reason: Not used
CVE-2025-62807Rejected reason: Not used
CVE-2025-62806Rejected reason: Not used
CVE-2025-62805Rejected reason: Not used
CVE-2025-62804Rejected reason: Not used
CVE-2025-11575HIGH8.8Incorrect Default Permissions vulnerability in MongoDB Atlas SQL ODBC driver on Windows allows Privilege Escalation.This...
CVE-2025-62710MEDIUM5.9Sakai is a Collaboration and Learning Environment. Prior to versions 23.5 and 25.0, EncryptionUtilityServiceImpl initial...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now