2025 CVE Vulnerabilities

45,221 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-53092MEDIUM6.5Strapi is an open source headless content management system. Strapi versions prior to 5.20.0 contain a CORS misconfigura...
CVE-2025-36128HIGH7.5IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of th...
CVE-2025-25298MEDIUM5.3Strapi is an open source headless CMS. The @strapi/core package before version 5.10.3 does not enforce a maximum passwor...
CVE-2025-11854Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-22381. Reason: This candidate is a ...
CVE-2025-9559MEDIUM6.5Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user inter...
CVE-2025-62496HIGH8.8A vulnerability exists in the QuickJS engine's BigInt string parsing logic (js_bigint_from_string) when attempting to cr...
CVE-2025-62495HIGH8.8An integer overflow vulnerability exists in the QuickJS regular expression engine (libregexp) due to an inconsistent rep...
CVE-2025-62494HIGH8.8A type confusion vulnerability exists in the handling of the string addition (+) operation within the QuickJS engine. ...
CVE-2025-62493MEDIUM6.5A vulnerability exists in the QuickJS engine's BigInt string conversion logic (js_bigint_to_string1) due to an incorrect...
CVE-2025-62492MEDIUM6.5A vulnerability stemming from floating-point arithmetic precision errors exists in the QuickJS engine's implementation o...
CVE-2025-62491HIGH8.8A Use-After-Free (UAF) vulnerability exists in the QuickJS engine's standard library when iterating over the global list...
CVE-2025-62490HIGH8.8In quickjs, in js_print_object, when printing an array, the function first fetches the array length and then loops over ...
CVE-2025-55035MEDIUM6.1Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a se...
CVE-2025-11851LOW3.5A vulnerability has been found in Apeman ID71 EN75.8.53.20. The affected element is an unknown function of the file /set...
CVE-2025-11842MEDIUM6.3A security vulnerability has been detected in Shazwazza Smidge up to 4.5.1. The impacted element is an unknown function ...
CVE-2025-11840MEDIUM5.5A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. E...
CVE-2025-61543HIGH7.1A Host Header Injection vulnerability exists in the password reset functionality of CraftMyCMS 4.0.2.2. The system uses ...
CVE-2025-61541HIGH7.1Webmin 2.510 is vulnerable to a Host Header Injection in the password reset functionality (forgot_send.cgi). The reset l...
CVE-2025-61540MEDIUM6.5SQL injection vulnerability in Ultimate PHP Board 2.2.7 via the username field in lostpassword.php.
CVE-2025-61539MEDIUM6.1Cross site scripting (XSS) vulnerability in Ultimate PHP Board 2.2.7 via the u_name parameter in lostpassword.php.
CVE-2025-61536HIGH8.2FelixRiddle dev-jobs-handlebars 1.0 uses absolute password-reset (magic) links using the untrusted `req.headers.host` he...
CVE-2025-41254MEDIUM4.3STOMP over WebSocket applications may be vulnerable to a security bypass that allows an attacker to send unauthorized me...
CVE-2025-41253HIGH7.5The following versions of Spring Cloud Gateway Server Webflux may be vulnerable to the ability to expose environment var...
CVE-2025-36002MEDIUM5.5IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5, ...
CVE-2025-22381HIGH8.2Aggie 2.6.1 has a Host Header injection vulnerability in the forgot password functionality, allowing an attacker to rese...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now