2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-61189MEDIUM6.3Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. The endpoint is /sys/comment/addFil...
CVE-2025-61188MEDIUM6.3Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. This vulnerability allows attackers...
CVE-2025-59149MEDIUM6.2Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-59148HIGH7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-59147HIGH7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-58769LOW3.3auth0-PHP is an SDK for Auth0 Authentication and Management APIs. In versions 3.3.0 through 8.16.0, the Bulk User Import...
CVE-2025-57444MEDIUM6.1An authenticated cross-site scripting (XSS) vulnerability in the Administrative interface of Radware AlteonOS Web UI Man...
CVE-2025-56588HIGH8.8Dolibarr ERP & CRM v21.0.1 were discovered to contain a remote code execution (RCE) vulnerability in the User module con...
CVE-2025-59682MEDIUM6.5An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. The django.utils.archive.e...
CVE-2025-59681CRITICAL9.8An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), Query...
CVE-2025-58055MEDIUM4.3Discourse is an open-source community discussion platform. In versions 3.5.0 and below, the Discourse AI suggestion endp...
CVE-2025-58054MEDIUM5.4Discourse is an open-source community discussion platform. Versions 3.5.0 and below are vulnerable to XSS attacks throug...
CVE-2025-46205HIGH8.1A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to caus...
CVE-2025-43718LOW2.9Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSEGV via deeply nested structures within t...
CVE-2025-10578HIGH7.8A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.47.41.0. The ...
CVE-2025-8679CRITICAL9.8In ExtremeGuest Essentials before 25.5.0, captive-portal may permit unauthorized access via manual brute-force procedure...
CVE-2025-60991HIGH8.8A reflected cross-site scripted (XSS) vulnerability in Codazon Magento Themes v1.1.0.0 to v2.4.7 allows attackers to exe...
CVE-2025-57393HIGH8.8A stored cross-site scripting (XSS) in Kissflow Work Platform Kissflow Application Versions 7337 Account v2.0 to v4.2val...
CVE-2025-28357HIGH8.8A CRLF injection vulnerability in Neto CMS v6.313.0 through v6.314.0 allows attackers to execute arbitrary code via supp...
CVE-2025-61596Rejected reason: This is a fork and is not in the Rust registry.
CVE-2025-34182MEDIUM5.1In Deciso OPNsense before 25.7.4, when creating an "Interfaces: Devices: Point-to-Point" entry, the value of the paramet...
CVE-2025-20371HIGH8.8In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.10...
CVE-2025-20370MEDIUM4.9In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.1...
CVE-2025-20369MEDIUM6.5In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3....
CVE-2025-20368MEDIUM5.4In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now