2025 CVE Vulnerabilities

45,209 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-60280MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in Bang Resto v1.0 could allow an attacker to inject malicious JavaScript code ...
CVE-2025-22166HIGH7.5This High severity DoS (Denial of Service) vulnerability was introduced in version 2.0 of Confluence Data Center. Thi...
CVE-2025-12024Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2025-60934MEDIUM6.1Multiple stored cross-site scripting (XSS) vulnerabilities in the index.php component of HR Performance Solutions Perfor...
CVE-2025-60933MEDIUM6.1Multiple stored cross-site scripting (XSS) vulnerabilities in the Future Goals function of HR Performance Solutions Perf...
CVE-2025-60932MEDIUM6.1Multiple stored cross-site scripting (XSS) vulnerabilities in the Current Goals function of HR Performance Solutions Per...
CVE-2025-60344HIGH8.6A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attacker...
CVE-2025-59438MEDIUM5.3Mbed TLS through 3.6.4 has an Observable Timing Discrepancy.
CVE-2025-57521MEDIUM6.1Bambu Studio 2.1.1.52 and earlier is affected by a vulnerability that allows arbitrary code execution during application...
CVE-2025-56450MEDIUM6.5Log2Space Subscriber Management Software 1.1 is vulnerable to unauthenticated SQL injection via the `lead_id` parameter ...
CVE-2025-9339HIGH7.1SQL injection vulnerability in the fields of warehouse document filtering form in SIMPLE.ERP software allows logged-in u...
CVE-2025-11625CRITICAL9.8Improper host authentication vulnerability in wolfSSH version 1.4.20 and earlier clients that allows authentication bypa...
CVE-2025-11624CRITICAL9.8Potential stack buffer overwrite on the SFTP server side when receiving a malicious packet that has a handle size larger...
CVE-2025-11151HIGH8.2Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Sensitive System Information to an Unauthorized ...
CVE-2025-6239MEDIUM6.5Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Di...
CVE-2025-10020HIGH8.8Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability...
CVE-2025-9428HIGH8.8Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key u...
CVE-2025-10641HIGH7.1All WorkExaminer Professional traffic between monitoring client, console and server is transmitted as plain text. This a...
CVE-2025-10640CRITICAL9.8An unauthenticated attacker with access to TCP port 12306 of the WorkExaminer server can exploit missing server-side aut...
CVE-2025-10639HIGH8.8The WorkExaminer Professional server installation comes with an FTP server that is used to receive the client logs on TC...
CVE-2025-7473MEDIUM5.3Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection.
CVE-2025-5496LOW3.3ZohoCorp ManageEngine Endpoint Central versions earlier than 11.4.2508.14, 11.4.2516.06, and 11.4.2518.01 are affected b...
CVE-2025-10612MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in giSoft Info...
CVE-2025-26392MEDIUM4.6SolarWinds Observability Self-Hosted is susceptible to SQL injection vulnerability that may display sensitive data using...
CVE-2025-12004CRITICAL10Incorrect Permission Assignment for Critical Resource vulnerability in The Wikimedia Foundation Mediawiki - Lockdown Ext...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now