2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-53815——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ...
CVE-2025-53517——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ...
CVE-2025-69784HIGH8.8A local, non-privileged attacker can abuse a vulnerable IOCTL interface exposed by the OpenEDR 2.5.1.0 kernel driver to ...
CVE-2025-69783HIGH7.8A local attacker can bypass OpenEDR's 2.5.1.0 self-defense mechanism by renaming a malicious executable to match a trust...
CVE-2025-62319CRITICAL9.8Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Bool...
CVE-2025-57543MEDIUM6.1Cross Site scripting vulnerability (XSS) in NetBox 4.3.5 "comment" field on object forms. An attacker can inject arbitra...
CVE-2025-52649MEDIUM5.3HCL AION is affected by a vulnerability where certain identifiers may be predictable in nature. Predictable identifiers ...
CVE-2025-52646MEDIUM5.3HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmfu...
CVE-2025-52645MEDIUM5.3HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient aut...
CVE-2025-52644HIGH8.2HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of ...
CVE-2025-52643HIGH7.8HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isola...
CVE-2025-52642MEDIUM6.5HCL AION is affected by a vulnerability where internal filesystem paths may be exposed through application responses or ...
CVE-2025-52636HIGH7.5HCL AION is affected by a vulnerability related to the handling of upload size limits. Improper control or validation of...
CVE-2025-2274MEDIUM6.1Improper Neutralization of Input During Web Page Generation in Forcepoint Web Security (On-Prem) on Windows allows Store...
CVE-2025-71264MEDIUM5.3Mumble before 1.6.870 is prone to an out-of-bounds array access, which may result in denial of service (client crash).
CVE-2025-6969MEDIUM5.5in OpenHarmony v5.1.0 and prior versions allow a local attacker cause DOS through improper input.
CVE-2025-69246CRITICAL9.8Raytha CMS does not have any brute force protection mechanism implemented. It allows an attacker to send multiple automa...
CVE-2025-69245MEDIUM6.1Raytha CMS is vulnerable to Reflected XSS via returnUrl parameter in logon functionality. An attacker can craft a malici...
CVE-2025-69243MEDIUM5.3Raytha CMS is vulnerable to User Enumeration in password reset functionality. Difference in messages could allow an atta...
CVE-2025-69242MEDIUM6.1Raytha CMS is vulnerable to reflected XSS via the backToListUrl parameter. An attacker can craft a malicious URL which, ...
CVE-2025-69241MEDIUM5.4Raytha CMS is vulnerable to Stored XSS via FirstName and LastName parameters in profile editing functionality. Authentic...
CVE-2025-69240HIGH8.8Raytha CMS allows an attacker to spoof `X-Forwarded-Host` or `Host` headers to attacker controlled domain. The attacker ...
CVE-2025-69239LOW2.7Raytha CMS is vulnerable to Server-Side Request Forgery in the “Themes - Import from URL” feature. It allows an attacker...
CVE-2025-69238MEDIUM4.3Raytha CMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. Attacker can craft special website, wh...
CVE-2025-69237MEDIUM5.4Raytha CMS is vulnerable to Stored XSS via FieldValues[0].Value parameter in page creation functionality. Authenticated ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now