2025 CVE Vulnerabilities

45,223 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-61861HIGH8.4An out-of-bounds read vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially ...
CVE-2025-61860HIGH8.4An out-of-bounds read vulnerability exists in VS6MemInIF!set_temp_type_default of V-SFT v6.2.7.0 and earlier. Opening sp...
CVE-2025-61859HIGH8.4An out-of-bounds write vulnerability exists in VS6ComFile!CItemDraw::is_motion_tween of V-SFT v6.2.7.0 and earlier. Open...
CVE-2025-61858HIGH8.4An out-of-bounds write vulnerability exists in VS6ComFile!set_AnimationItem of V-SFT v6.2.7.0 and earlier. Opening speci...
CVE-2025-61857HIGH8.4An out-of-bounds write vulnerability exists in VS6ComFile!CItemExChange::WinFontDynStrCheck of V-SFT v6.2.7.0 and earlie...
CVE-2025-61856HIGH8.4A stack-based buffer overflow vulnerability exists in VS6ComFile!CV7BaseMap::WriteV7DataToRom of V-SFT v6.2.7.0 and earl...
CVE-2025-52635CRITICAL9.8A rusted types in scripts not enforced in CSP vulnerability has been identified in HCL AION.This issue affects AION:...
CVE-2025-52625HIGH7.5A vulnerability  Cacheable SSL Page Found vulnerability has been identified in HCL AION.  Cached data may expose cre...
CVE-2025-52624MEDIUM6.1A vulnerability  Bypass of the script allowlist configuration in HCL AION.  An incorrectly configured Content-Security-...
CVE-2025-11190MEDIUM5.4The Kiwire Captive Portal contains an open redirection issue via the login-url parameter, allowing an attacker to redire...
CVE-2025-11189HIGH7.3The Kiwire Captive Portal contains a reflected cross-site scripting (XSS) vulnerability within the login-url parameter, ...
CVE-2025-11188HIGH7.3The Kiwire Captive Portal contains a blind SQL injection in the nas-id parameter, allowing for SQL commands to be issued...
CVE-2025-52650MEDIUM6.1Inline script execution allowed in CSP vulnerability has been identified in HCL AION v2.0
CVE-2025-52634HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION This issue affects HCL AION: 2.0.
CVE-2025-52632HIGH7.5A Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL AION.This issue affects AION: 2.0.
CVE-2025-52630HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0.
CVE-2025-41089MEDIUM4.8Reflected Cross-Site Scripting (XSS) in Xibo CMS v4.1.2 from Xibo Signage, due to a lack of proper validation of user in...
CVE-2025-41088MEDIUM5.1Stored Cross-Site Scripting (XSS) in Xibo Signage's Xibo CMS v4.1.2, due to a lack of proper validation of user input. T...
CVE-2025-37727MEDIUM5.7Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preco...
CVE-2025-30001HIGH7.3Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from...
CVE-2025-25018MEDIUM5.4Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)
CVE-2025-25017MEDIUM6.1Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)
CVE-2025-52655LOW3.1Inclusion of Functionality from Untrusted Control Sphere vulnerability in HCL MyXalytics. v6.6 allows Loading third-part...
CVE-2025-40640MEDIUM5.4Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS du...
CVE-2025-62292MEDIUM4.3In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now