2025 CVE Vulnerabilities

45,224 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-11192HIGH8.6A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is enabled on...
CVE-2025-8291MEDIUM4.3The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset val...
CVE-2025-43914HIGH7.8Dell PowerProtect Data Domain BoostFS for Linux Ubuntu systems of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS...
CVE-2025-43911MEDIUM6.7Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3....
CVE-2025-43906MEDIUM6.7Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3....
CVE-2025-43890MEDIUM6.7Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3....
CVE-2025-3450CRITICAL10An Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and before...
CVE-2025-36156HIGH7.8IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11.4 is vulnerable to a stack-based buffer overflow, caused ...
CVE-2025-1826MEDIUM5.4IBM Engineering Requirements Management DOORS Next (IBM Jazz Foundation 7.0.2 to 7.0.2 iFix034, 7.0.3 to 7.0.3 iFix016, ...
CVE-2025-11403CRITICAL9.8A vulnerability was found in SourceCodester Hotel and Lodge Management System 1.0. Affected by this issue is some unknow...
CVE-2025-11402CRITICAL9.8A vulnerability has been found in SourceCodester Hotel and Lodge Management System 1.0. Affected by this vulnerability i...
CVE-2025-56243MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability was found in the register.php page of PuneethReddyHC Event Management System ...
CVE-2025-52021CRITICAL9.8A SQL Injection vulnerability exists in the edit_product.php file of PuneethReddyHC Online Shopping System Advanced 1.0....
CVE-2025-11401CRITICAL9.8A flaw has been found in SourceCodester Hotel and Lodge Management System 1.0. Affected is an unknown function of the fi...
CVE-2025-60312MEDIUM6.1Sourcecodester Markdown to HTML Converter v1.0 is vulnerable to a Cross-Site Scripting (XSS) in the "Markdown Input" fie...
CVE-2025-11400CRITICAL9.8A vulnerability was detected in SourceCodester Hotel and Lodge Management System 1.0. This impacts an unknown function o...
CVE-2025-11399CRITICAL9.8A security vulnerability has been detected in SourceCodester Hotel and Lodge Management System 1.0. This affects an unkn...
CVE-2025-61772HIGH7.5Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, `Rack::Multipart::Parser` c...
CVE-2025-61771HIGH7.5Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, ``Rack::Multipart::Parser` ...
CVE-2025-61770HIGH7.5Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, `Rack::Multipart::Parser` b...
CVE-2025-11398HIGH8.8A weakness has been identified in SourceCodester Hotel and Lodge Management System 1.0. The impacted element is an unkno...
CVE-2025-59425HIGH7.5vLLM is an inference and serving engine for large language models (LLMs). Before version 0.11.0rc2, the API key support ...
CVE-2025-57564HIGH8.2CubeAPM nightly-2025-08-01-1 allow unauthenticated attackers to inject arbitrary log entries into production systems via...
CVE-2025-54406HIGH8.8Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A...
CVE-2025-54405HIGH8.8Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now