2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-20367MEDIUM5.4In Splunk Enterprise versions below 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2...
CVE-2025-20366MEDIUM6.5In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.111, 9.3....
CVE-2025-20361MEDIUM4.8A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Uni...
CVE-2025-20357MEDIUM5.4A vulnerability in the web-based management interface of Cisco Cyber Vision Center could allow an authenticated, remote ...
CVE-2025-20356MEDIUM5.4A vulnerability in the web-based management interface of Cisco Cyber Vision Center could allow an authenticated, remote ...
CVE-2025-11233MEDIUM6.3Starting from Rust 1.87.0 and before Rust 1.89.0, the tier 3 Cygwin target (`x86_64-pc-cygwin`) didn't correctly handle ...
CVE-2025-56515HIGH8.8File upload vulnerability in Fiora chat application 1.0.0 through user avatar upload functionality. The application fail...
CVE-2025-56514MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Fiora chat application 1.0.0 allows executes arbitrary JavaScript when malic...
CVE-2025-61045CRITICAL9.8TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter i...
CVE-2025-61044CRITICAL9.8TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the agentName param...
CVE-2025-59687MEDIUM4.3IMPAQTR Aurora before 1.36 allows Insecure Direct Object Reference attacks against the users list, organization details,...
CVE-2025-59686MEDIUM6.5Kazaar 1.25.12 allows /api/v1/org-id/orders/order-id/documents calls with a modified order-id.
CVE-2025-59685MEDIUM5.3Kazaar 1.25.12 allows a JWT with none in the alg field.
CVE-2025-59684HIGH8.8DigiSign DigiSigner ONE 1.0.4.60 allows DLL Hijacking.
CVE-2025-57275MEDIUM5.5Storage Performance Development Kit (SPDK) 25.05 is vulnerable to Buffer Overflow in the NVMe-oF target component in SPD...
CVE-2025-52042HIGH8.2In Frappe ERPNext 15.57.5, the function get_rfq_containing_supplier() at erpnext/buying/doctype/request_for_quotation/re...
CVE-2025-52041HIGH8.2In Frappe ERPNext 15.57.5, the function get_stock_balance_for() at erpnext/stock/doctype/stock_reconciliation/stock_reco...
CVE-2025-52040HIGH8.2In Frappe ERPNext 15.57.5, the function get_blanket_orders() at erpnext/controllers/queries.py is vulnerable to SQL Inje...
CVE-2025-52039HIGH8.2In Frappe ERPNext 15.57.5, the function get_material_requests_based_on_supplier() at erpnext/stock/doctype/material_requ...
CVE-2025-41421MEDIUM4.7Improper handling of symbolic links in the TeamViewer Full Client and Host for Windows — in versions prior to 15.70 of T...
CVE-2025-40648MEDIUM4.8Stored Cross-Site Scripting (XSS) vulnerability in Issabel v5.0.0, consisting of a stored XSS due to a lack of proper va...
CVE-2025-40647MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in Issabel v5.0.0, consisting of a stored XSS due to a lack of proper va...
CVE-2025-10847HIGH8.4DX Unified Infrastructure Management (Nimsoft/UIM) and below contains an improper ACL handling vulnerability in the robo...
CVE-2025-61622CRITICAL9.8Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from...
CVE-2025-39928MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: i2c: rtl9300: ensure data length is within supporte...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now