2025 CVE Vulnerabilities

45,224 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-61998MEDIUM4.8OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject JavaScript or other content as a URL within t...
CVE-2025-61997MEDIUM4.8OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject JavaScript or other content within the Annual...
CVE-2025-61996MEDIUM4.8OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject JavaScript or other content within the Annual...
CVE-2025-11417HIGH8.8A weakness has been identified in Campcodes Advanced Online Voting Management System 1.0. This vulnerability affects unk...
CVE-2025-6046Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-43822MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.15 through 7.4.3.111, and Liferay DXP...
CVE-2025-11416CRITICAL9.8A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of ...
CVE-2025-11415CRITICAL9.8A vulnerability was identified in PHPGurukul Beauty Parlour Management System 1.1. Affected by this issue is some unknow...
CVE-2025-11414MEDIUM5.5A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry ...
CVE-2025-10904Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-43823MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Commerce Search Result widget in Liferay Portal 7.4.0 through 7.4.3.111,...
CVE-2025-11413MEDIUM5.5A vulnerability was found in GNU Binutils 2.45. Affected is the function elf_link_add_object_symbols of the file bfd/elf...
CVE-2025-11412MEDIUM5.5A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd...
CVE-2025-11410HIGH8.8A flaw has been found in Campcodes Advanced Online Voting Management System 1.0. This affects an unknown function of the...
CVE-2025-62187LOW3.3In Ankitects Anki before 25.02.6, crafted sound file references could cause files to be written to arbitrary locations o...
CVE-2025-62186HIGH7.8Ankitects Anki before 25.02.5 allows a crafted shared deck on Windows to execute arbitrary commands when playing audio b...
CVE-2025-62185HIGH7.8In Ankitects Anki before 25.02.5, a crafted shared deck can place a YouTube downloader executable in the media folder, a...
CVE-2025-34252Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. This vulnerability has been ...
CVE-2025-11409HIGH8.8A vulnerability was detected in Campcodes Advanced Online Voting Management System 1.0. The impacted element is an unkno...
CVE-2025-11408CRITICAL9.8A security vulnerability has been detected in D-Link DI-7001 MINI 24.04.18B1. The affected element is an unknown functio...
CVE-2025-6242HIGH7.1A Server-Side Request Forgery (SSRF) vulnerability exists in the MediaConnector class within the vLLM project's multimod...
CVE-2025-61910HIGH7.5The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN). A BP...
CVE-2025-44824MEDIUM6.5Nagios Log Server before 2024R1.3.2 allows authenticated users (with read-only API access) to stop the Elasticsearch ser...
CVE-2025-44823HIGH8.8Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagi...
CVE-2025-43910MEDIUM4.4Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now