2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-15604CRITICAL9.8Amon2 versions before 6.17 for Perl use an insecure random_string implementation for security functions. In versions 6....
CVE-2025-9497CRITICAL9.8Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This...
CVE-2025-15445MEDIUM5.4The Restaurant Cafeteria WordPress theme through 0.4.6 exposes insecure admin-ajax actions without nonce or capability c...
CVE-2025-12886HIGH7.2The Oxygen Theme theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, ...
CVE-2025-15612HIGH8.1Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k...
CVE-2025-15617HIGH8.1Wazuh version 4.12.0 contains an exposure vulnerability in GitHub Actions workflow artifacts that allows attackers to ex...
CVE-2025-15616HIGH7.2Wazuh wazuh-agent and wazuh-manager versions 2.1.0 before 4.8.0 contain multiple shell injection and untrusted search pa...
CVE-2025-15615HIGH7.5Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-i...
CVE-2025-15381HIGH7.1In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not p...
CVE-2025-69988MEDIUM6.5BS Producten Petcam 33.1.0.0818 is vulnerable to Incorrect Access Control. An unauthenticated attacker in physical proxi...
CVE-2025-69986HIGH7.2A buffer overflow vulnerability exists in the ONVIF GetStreamUri function of LSC Indoor Camera V7.6.32. The application ...
CVE-2025-61190MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in DSpace JSPUI 6.5 within the search/discover ...
CVE-2025-13478HIGH8.4Cache misconfiguration vulnerability in OpenText Identity Manager on Windows, Linux allows remote authenticated users to...
CVE-2025-59032HIGH7.5ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSi...
CVE-2025-59031MEDIUM4.3Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachmen...
CVE-2025-59028HIGH7.5When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentica...
CVE-2025-12805HIGH8.1A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator. This vulnerability allows unauthorized access to ...
CVE-2025-55264MEDIUM5.5HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a s...
CVE-2025-55263HIGH7.5HCL Aftermarket DPC is affected by Hardcoded Sensitive Data which allows attacker to gain access to the source code or i...
CVE-2025-55262HIGH7.5HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensiti...
CVE-2025-55261CRITICAL9.8HCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his pri...
CVE-2025-55277MEDIUM6.5HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerability using which an attacker may make us...
CVE-2025-55276MEDIUM5.3HCL Aftermarket DPC is affected by Internal IP Disclosure vulnerability will give attackers a clearer map of the organiz...
CVE-2025-55275HIGH8.1HCL Aftermarket DPC is affected by Admin Session Concurrency vulnerability using which an attacker can exploit concurren...
CVE-2025-55274MEDIUM4.3HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability. CORS misconfigurations includes the expo...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now