2025 CVE Vulnerabilities

45,224 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-59957HIGH7An Origin Validation Error vulnerability in an insufficient protected file of Juniper Networks Junos OS on EX4600 Series...
CVE-2025-56426MEDIUM6.5An issue WebKul Bagisto v.2.3.6 allows a remote attacker to execute arbitrary code via the Cart/Checkout API endpoint, s...
CVE-2025-52961HIGH7.1An Uncontrolled Resource Consumption vulnerability in the Connectivity Fault Management (CFM) daemon and the Connectivit...
CVE-2025-52960HIGH8.2A Buffer Copy without Checking Size of Input vulnerability in the Session Initialization Protocol (SIP) ALG of Juniper...
CVE-2025-11198HIGH8.5A Missing Authentication for Critical Function vulnerability in Juniper Networks Security Director Policy Enforcer allow...
CVE-2025-10284CRITICAL9.6BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arb...
CVE-2025-10283CRITICAL9.6BBOT's gitdumper module could be abused to execute commands through a malicious git repository.
CVE-2025-10282MEDIUM4.7BBOT's gitlab module could be abused to disclose a GitLab API key to an attacker controlled server with a malicious form...
CVE-2025-10281MEDIUM4.7BBOT's git_clone module could be abused to disclose a GitHub API key to an attacker controlled server with a malicious f...
CVE-2025-56683CRITICAL9.6A cross-site scripting (XSS) vulnerability in the component /app/marketplace.html of Logseq v0.10.9 allows attackers to ...
CVE-2025-45095HIGH7.3Lavasoft Web Companion (also known as Ad-Aware WebCompanion) versions 8.9.0.1091 through 12.1.3.1037 installs the DCISer...
CVE-2025-39664MEDIUM6.5Insufficient escaping in the report scheduler within Checkmk <2.4.0p13, <2.3.0p38, <2.2.0p46 and 2.1.0 (EOL) allows auth...
CVE-2025-32919HIGH7.8Use of an insecure temporary directory in the Windows License plugin for the Checkmk Windows Agent allows Privilege Esca...
CVE-2025-32916MEDIUM4.3Potential use of sensitive information in GET requests in Checkmk GmbH's Checkmk versions <2.4.0p13, <2.3.0p38, <2.2.0p4...
CVE-2025-62228HIGH8.8Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted databas...
CVE-2025-36225MEDIUM4.3IBM Aspera 5.0.0 through 5.0.13.1 could disclose sensitive user information from the system to an authenticated user d...
CVE-2025-36171MEDIUM4.9IBM Aspera Faspex 5.0.0 through 5.0.13.1 could allow a privileged user to cause a denial of service from improperly vali...
CVE-2025-11561HIGH8.8A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems....
CVE-2025-39963HIGH7.8In the Linux kernel, the following vulnerability has been resolved: io_uring: fix incorrect io_kiocb reference in io_li...
CVE-2025-39962HIGH7.8In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix untrusted unsigned subtract Fix the fol...
CVE-2025-39961MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: iommu/amd/pgtbl: Fix possible race while increase p...
CVE-2025-39960HIGH7.8In the Linux kernel, the following vulnerability has been resolved: gpiolib: acpi: initialize acpi_gpio_info struct Si...
CVE-2025-10240HIGH8.8A vulnerability exists in the Progress Flowmon web application prior to version 12.5.5, whereby a user who clicks a mali...
CVE-2025-10239HIGH7.2In Flowmon versions prior to 12.5.5, a vulnerability has been identified that allows a user with administrator privilege...
CVE-2025-9371MEDIUM6.4The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘page_title’ parameter in all versi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now