2025 CVE Vulnerabilities

45,139 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-71257CRITICAL9.1BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to imprope...
CVE-2025-14716MEDIUM6.5Improper Authentication vulnerability in Secomea GateManager (webserver modules) allows Authentication Bypass.This issue...
CVE-2025-68836HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Markbeljaars Table...
CVE-2025-67618HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ArtstudioWorks Bro...
CVE-2025-62043MEDIUM6.5Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPSight WPCasa all...
CVE-2025-60237CRITICAL9.8Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from...
CVE-2025-60233CRITICAL9.8Deserialization of Untrusted Data vulnerability in Themeton Zuut allows Object Injection.This issue affects Zuut: from n...
CVE-2025-53222HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Opt-...
CVE-2025-50001HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Comp...
CVE-2025-32223MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly ...
CVE-2025-36051MEDIUM5.5IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 stores potentially sensitive information in configuration files th...
CVE-2025-15051MEDIUM5.4IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows u...
CVE-2025-13995MEDIUM5IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 could allow an attacker with access to one tenant to access hostna...
CVE-2025-15031CRITICAL9.1A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar a...
CVE-2025-58112HIGH8.8Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034) allows the generation of customized reports v...
CVE-2025-71270MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: LoongArch: Enable exception fixup for specific ADE ...
CVE-2025-71269MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: do not free data reservation in fallback fro...
CVE-2025-71268MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: fix reservation leak in some error paths whe...
CVE-2025-67830CRITICAL9.8Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection.
CVE-2025-67829CRITICAL9.8Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection.
CVE-2025-55046HIGH8.1MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted content s...
CVE-2025-55045HIGH7.1The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address information...
CVE-2025-55044HIGH8.8The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from the tra...
CVE-2025-55043MEDIUM6.5MuraCMS through 10.1.10 contains a CSRF vulnerability in the bundle creation functionality (csettings.cfc createBundle m...
CVE-2025-55041HIGH8MuraCMS through 10.1.10 contains a CSRF vulnerability in the Add To Group functionality for user management (cUsers.cfc ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now