2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-56676MEDIUM5.4TitanSystems Zender v3.9.7 contains an account takeover vulnerability in its password reset functionality. A temporary p...
CVE-2025-56572HIGH7.5An issue in finance.js v.4.1.0 allows a remote attacker to cause a denial of service via the seekZero() parameter.
CVE-2025-56571HIGH7.5Finance.js v4.1.0 contains a Denial of Service (DoS) vulnerability via the IRR function’s depth parameter. Improper hand...
CVE-2025-56018MEDIUM6.1SourceCodester Web-based Pharmacy Product Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in Category...
CVE-2025-55797MEDIUM6.5An improper access control vulnerability in FormCms v0.5.4 in the /api/schemas/history/[schemaId] endpoint allows unauth...
CVE-2025-54477MEDIUM5.3Improper handling of authentication requests lead to a user enumeration vector in the passkey authentication method.
CVE-2025-54476MEDIUM4.8Improper handling of input could lead to an XSS vector in the checkAttribute method of the input filter framework class.
CVE-2025-7779HIGH8.8Local privilege escalation due to insecure XPC service configuration. The following products are affected: Acronis True ...
CVE-2025-7493CRITICAL9.1A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE...
CVE-2025-57852MEDIUM6.4A container privilege escalation flaw was found in KServe ModelMesh container images. This issue stems from the /etc/pas...
CVE-2025-56301HIGH7.5An issue was discovered in Chipsalliance Rocket-Chip commit f517abbf41abb65cea37421d3559f9739efd00a9 (2025-01-29) allowi...
CVE-2025-28016MEDIUM4.8A Reflected Cross-Site Scripting (XSS) vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User Re...
CVE-2025-11178HIGH7.3Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (...
CVE-2025-9232MEDIUM5.9Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_p...
CVE-2025-9231MEDIUM6.5Issue summary: A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 ...
CVE-2025-9230HIGH7.5Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an ou...
CVE-2025-52050MEDIUM6.5In Frappe ERPNext 15.57.5, the function get_loyalty_program_details_with_points() at erpnext/accounts/doctype/loyalty_pr...
CVE-2025-52049MEDIUM6.5In Frappe ErpNext v15.57.5, the function get_timesheet_detail_rate() at erpnext/projects/doctype/timesheet/timesheet.py ...
CVE-2025-52047MEDIUM6.5In Frappe ErpNext v15.57.5, the function get_income_account() at erpnext/controllers/queries.py is vulnerable to SQL Inj...
CVE-2025-52043MEDIUM6.5In Frappe ERPNext v15.57.5, the function import_coa() at erpnext/accounts/doctype/chart_of_accounts_importer/chart_of_ac...
CVE-2025-34217CRITICAL9.8Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) contain an undocumente...
CVE-2025-11153HIGH7.5JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 143.0.3.
CVE-2025-11152HIGH8.6Sandbox escape due to integer overflow in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143....
CVE-2025-10859MEDIUM4Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing info...
CVE-2025-10217MEDIUM6A vulnerability exists in Asset Suite for an authenticated user to manipulate the content of performance related log dat...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now