2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-57424HIGH7.3A stored cross-site scripting (XSS) vulnerability exists in the MyCourts v3 application within the LTA number profile fi...
CVE-2025-41252HIGH7.5Description: VMware NSX contains a username enumeration vulnerability. An unauthenticated malicious actor may exploit th...
CVE-2025-41251HIGH8.1VMware NSX contains a weak password recovery mechanism vulnerability. An unauthenticated malicious actor may exploit thi...
CVE-2025-36099MEDIUM4.9IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted...
CVE-2025-34196CRITICAL9.8Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application prior to 25.1.141...
CVE-2025-57483HIGH8.1A reflected cross-site scripting (XSS) vulnerability in tawk.to chatbox widget v4 allows attackers to execute arbitrary ...
CVE-2025-57197MEDIUM6In the Payeer Android application 2.5.0, an improper access control vulnerability exists in the authentication flow for ...
CVE-2025-56807MEDIUM6.1A cross-site scripting (XSS) vulnerability in FairSketch RISE Ultimate Project Manager & CRM 3.9.4 allows an administrat...
CVE-2025-43400MEDIUM6.3An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.1 and iPadOS 1...
CVE-2025-41250HIGH8.5VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on ...
CVE-2025-7104HIGH7.5A mass assignment vulnerability exists in danny-avila/librechat, affecting all versions. This vulnerability allows attac...
CVE-2025-61659MEDIUM6.8bash-git-prompt 2.6.1 through 2.7.1 insecurely uses the /tmp/git-index-private$$ file, which has a predictable name.
CVE-2025-56795CRITICAL9Mealie 3.0.1 and earlier is vulnerable to Stored Cross-Site Scripting (XSS) in the recipe creation functionality. Unsani...
CVE-2025-56234HIGH7.5AT_NA2000 from Nanda Automation Technology vendor has a denial-of-service vulnerability. For the processing of TCP RST p...
CVE-2025-56233HIGH7.5Openindiana, kernel SunOS 5.11 has a denial of service vulnerability. For the processing of TCP packets with RST or SYN ...
CVE-2025-51495HIGH7.5An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially cr...
CVE-2025-41245MEDIUM4.9VMware Aria Operations contains an information disclosure vulnerability. A malicious actor with non-administrative privi...
CVE-2025-41244HIGH7.8VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with...
CVE-2025-41246HIGH7.6VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls...
CVE-2025-11155MEDIUM6.8The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is n...
CVE-2025-57516HIGH8.2OS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b allowing attackers to e...
CVE-2025-56449HIGH8.2A security vulnerability was identified in Obsidian Scheduler's REST API 5.0.0 thru 6.3.0. If an account is locked out d...
CVE-2025-55795LOW3.5The openml/openml.org web application version v2.0.20241110 uses incremental user IDs and insufficient email ownership v...
CVE-2025-36352MEDIUM5.4IBM License Metric Tool 9.2.0 through 9.2.40 is vulnerable to stored cross-site scripting. This vulnerability allows an ...
CVE-2025-36351MEDIUM4.3IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in the REST A...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now