2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-1060HIGH8.7CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists that could result in the exposure of data ...
CVE-2025-1059HIGH8.7CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause communications to st...
CVE-2025-1058HIGH8.1CWE-494: Download of Code Without Integrity Check vulnerability exists that could render the device inoperable when mali...
CVE-2025-1227HIGH8.8A vulnerability was found in ywoa up to 2024.07.03. It has been rated as critical. This issue affects the function selec...
CVE-2025-0110HIGH8.6A command injection vulnerability in the Palo Alto Networks PAN-OS OpenConfig plugin enables an authenticated administra...
CVE-2025-1224HIGH8.8A vulnerability classified as critical was found in ywoa up to 2024.07.03. This vulnerability affects the function listN...
CVE-2025-25283HIGH7.5parse-duraton is software that allows users to convert a human readable duration to milliseconds. Versions prior to 2.1....
CVE-2025-25205HIGH8.2Audiobookshelf is a self-hosted audiobook and podcast server. Starting in version 2.17.0 and prior to version 2.19.1, a ...
CVE-2025-1216HIGH8.8A vulnerability, which was classified as critical, has been found in ywoa up to 2024.07.03. This issue affects the funct...
CVE-2025-1215HIGH7.8A vulnerability classified as problematic was found in vim up to 9.1.1096. This vulnerability affects unknown code of th...
CVE-2025-1146HIGH8.1CrowdStrike uses industry-standard TLS (transport layer security) to secure communications from the Falcon sensor to the...
CVE-2025-0937HIGH7.1Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wildcard namespace can bypass the ACL Poli...
CVE-2025-25200HIGH7.5Koa is expressive middleware for Node.js using ES2017 async functions. Prior to versions 0.21.2, 1.7.1, 2.15.4, and 3.0....
CVE-2025-25199HIGH7.5go-crypto-winnative Go crypto backend for Windows using Cryptography API: Next Generation (CNG). Prior to commit f49c8e1...
CVE-2025-25198HIGH8.8mailcow: dockerized is an open source groupware/email suite based on docker. Prior to version 2025-01a, a vulnerability ...
CVE-2025-1214HIGH8.8A vulnerability classified as critical has been found in pihome-shc PiHome 2.0. This affects an unknown part of the file...
CVE-2025-25743HIGH7.2D-Link DIR-853 A1 FW1.20B07 was discovered to contain a command injection vulnerability in the SetVirtualServerSettings ...
CVE-2025-1210HIGH8.8A vulnerability classified as critical was found in code-projects Wazifa System 1.0. Affected by this vulnerability is a...
CVE-2025-1244HIGH8.8A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execut...
CVE-2025-1212HIGH7.5An information disclosure vulnerability in GitLab CE/EE affecting all versions from 8.3 prior to 17.6.5, 17.7 prior to 1...
CVE-2025-1206HIGH8.8A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. This affects an unk...
CVE-2025-1042HIGH7.5An insecure direct object reference vulnerability in GitLab EE affecting all versions from 15.7 prior to 17.6.5, 17.7 pr...
CVE-2025-26378HIGH8.8A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 ...
CVE-2025-26377HIGH8.1A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 ...
CVE-2025-26375HIGH8.8A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now