2025 CVE Vulnerabilities

45,213 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-61908MEDIUM6.5Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, when creating an invali...
CVE-2025-61907MEDIUM6.5Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to th...
CVE-2025-61330MEDIUM6.5A hard-coded weak password vulnerability has been discovered in all Magic-branded devices from Chinese network equipment...
CVE-2025-60641MEDIUM6.5The file mexcel.php in the Vfront 0.99.52 codebase contains a vulnerable call to unserialize(base64_decode($_POST['mexce...
CVE-2025-60639MEDIUM6.5Hardcoded credentials in gsigel14 ATLAS-EPIC commit f29312c (2025-05-26).
CVE-2025-34519HIGH7.5Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an insecure hashing algorithm vulnerability. The product ...
CVE-2025-34518HIGH7.5Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a relative path traversal vulnerability in get_file_conte...
CVE-2025-34517HIGH7.5Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an absolute path traversal vulnerability in get_file_cont...
CVE-2025-34516CRITICAL9.8Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an...
CVE-2025-34515CRITICAL9.8Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in...
CVE-2025-34514HIGH8.8Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection vulnerabilities in mul...
CVE-2025-34513CRITICAL9.8Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_...
CVE-2025-34512MEDIUM6.1Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a reflected cross-site scripting (XSS) vulnerability in i...
CVE-2025-61789MEDIUM6.5Icinga DB Web provides a graphical interface for Icinga monitoring. Before 1.1.4 and 1.2.3, an authorized user with acce...
CVE-2025-58051MEDIUM6.5Nextcloud Tables allows you to create your own tables with individual columns. Prior 0.7.6, 0.8.8, and 0.9.5, when impor...
CVE-2025-56700MEDIUM5.4Boolean SQL injection vulnerability in the web app of Base Digitale Group spa product Centrax Open PSIM version 6.1 allo...
CVE-2025-56699MEDIUM5.4SQL injection vulnerability in the cmd component of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows...
CVE-2025-53092MEDIUM6.5Strapi is an open source headless content management system. Strapi versions prior to 5.20.0 contain a CORS misconfigura...
CVE-2025-36128HIGH7.5IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of th...
CVE-2025-25298MEDIUM5.3Strapi is an open source headless CMS. The @strapi/core package before version 5.10.3 does not enforce a maximum passwor...
CVE-2025-11854Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-22381. Reason: This candidate is a ...
CVE-2025-9559MEDIUM6.5Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user inter...
CVE-2025-62496HIGH8.8A vulnerability exists in the QuickJS engine's BigInt string parsing logic (js_bigint_from_string) when attempting to cr...
CVE-2025-62495HIGH8.8An integer overflow vulnerability exists in the QuickJS regular expression engine (libregexp) due to an inconsistent rep...
CVE-2025-62494HIGH8.8A type confusion vulnerability exists in the handling of the string addition (+) operation within the QuickJS engine. ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now