2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-61715Rejected reason: Not used
CVE-2025-61714Rejected reason: Not used
CVE-2025-61792MEDIUM6.4Quadient DS-700 iQ devices through 2025-09-30 might have a race condition during the quick clicking of (in order) the Qu...
CVE-2025-55191MEDIUM5.3Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions between 2.1.0 and 2.14.19, 3.2.0-rc1,...
CVE-2025-43826MEDIUM5.4Stored cross-site scripting (XSS) vulnerabilities in Web Content translation in Liferay Portal 7.4.0 through 7.4.3.112, ...
CVE-2025-24525HIGH8.7Keysight Ixia Vision has an issue with hardcoded cryptographic material which may allow an attacker to intercept or dec...
CVE-2025-56392HIGH8.1An Insecure Direct Object Reference (IDOR) in the /dashboard/notes endpoint of Syaqui Collegetivity v1.0.0 allows attack...
CVE-2025-36262MEDIUM4.9IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 could allow a malicious privileged user to...
CVE-2025-36132MEDIUM5.4IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 is vulnerable to cross-site scripting. This ...
CVE-2025-10659CRITICAL9.8The Telenium Online Web Application is vulnerable due to a PHP endpoint accessible to unauthenticated network users that...
CVE-2025-56132HIGH7.3LiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The appli...
CVE-2025-43827MEDIUM4.3Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 through 7.4.3.117, and o...
CVE-2025-57254MEDIUM6.5An SQL injection vulnerability in user-login.php and index.php of Karthikg1908 Hospital Management System (HMS) 1.0 allo...
CVE-2025-56675LOW3.5The EKEN video doorbell T6 BT60PLUS_MAIN_V1.0_GC1084_20230531 periodically sends debug logs to the EKEN cloud servers wi...
CVE-2025-56513CRITICAL9.8NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks. An a...
CVE-2025-56200MEDIUM6.1A URL validation bypass vulnerability exists in validator.js through version 13.15.15. The isURL() function uses '://' a...
CVE-2025-23293HIGH8.7NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause...
CVE-2025-23292MEDIUM4.6NVIDIA Delegated Licensing Service for all appliance platforms contains a SQL injection vulnerability where an User/Atta...
CVE-2025-23291LOW2.4NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause...
CVE-2025-11195LOW3.3Rapid7 AppSpider Pro versions below 7.5.021 suffer from a project name validation vulnerability, whereby an attacker can...
CVE-2025-10725CRITICAL9.9A flaw was found in Red Hat Openshift AI Service. A low-privileged attacker with access to an authenticated account, for...
CVE-2025-56520MEDIUM5.3Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_...
CVE-2025-56207MEDIUM6.5A security flaw in the '_transfer' function of a smart contract implementation for Money Making Opportunity (MMO), an Et...
CVE-2025-6034HIGH8.5There is a memory corruption vulnerability due to an out of bounds read in DefaultFontOptions() when using SymbolEditor ...
CVE-2025-6033HIGH8.5There is a memory corruption vulnerability due to an out of bounds write in XML_Serialize() when using SymbolEditor in N...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now