2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-67113CRITICAL9.8OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware be...
CVE-2025-67112CRITICAL9.8Use of a hard-coded AES-256-CBC key in the configuration backup/restore implementation of Small Cell Sercomm SCE4255W (F...
CVE-2025-69720HIGH7.8The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in prog...
CVE-2025-71260HIGH8.8BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in ...
CVE-2025-71259HIGH7.1BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in ...
CVE-2025-71258HIGH7.1BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in ...
CVE-2025-71257CRITICAL9.1BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to imprope...
CVE-2025-14716MEDIUM6.5Improper Authentication vulnerability in Secomea GateManager (webserver modules) allows Authentication Bypass.This issue...
CVE-2025-68836HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Markbeljaars Table...
CVE-2025-67618HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ArtstudioWorks Bro...
CVE-2025-62043MEDIUM6.5Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPSight WPCasa all...
CVE-2025-60237CRITICAL9.8Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from...
CVE-2025-60233CRITICAL9.8Deserialization of Untrusted Data vulnerability in Themeton Zuut allows Object Injection.This issue affects Zuut: from n...
CVE-2025-53222HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Opt-...
CVE-2025-50001HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Comp...
CVE-2025-32223MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly ...
CVE-2025-36051MEDIUM5.5IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 stores potentially sensitive information in configuration files th...
CVE-2025-15051MEDIUM5.4IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows u...
CVE-2025-13995MEDIUM5IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 could allow an attacker with access to one tenant to access hostna...
CVE-2025-15031CRITICAL9.1A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar a...
CVE-2025-58112HIGH8.8Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034) allows the generation of customized reports v...
CVE-2025-71270MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: LoongArch: Enable exception fixup for specific ADE ...
CVE-2025-71269MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: do not free data reservation in fallback fro...
CVE-2025-71268MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: fix reservation leak in some error paths whe...
CVE-2025-67830CRITICAL9.8Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now