2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-11028HIGH7.5A security flaw has been discovered in givanz Vvveb up to 1.0.7.2. This affects an unknown part of the component Image H...
CVE-2025-11027MEDIUM5.4A vulnerability was identified in givanz Vvveb up to 1.0.7.2. Affected by this issue is some unknown functionality of th...
CVE-2025-6396MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Webbeyaz We...
CVE-2025-57292MEDIUM6.1Todoist v8484 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload functionality. The applica...
CVE-2025-55187CRITICAL9.9In DriveLock 24.1.4 before 24.1.5, 24.2.5 before 24.2.6, and 25.1.2 before 25.1.4, attackers can gain elevated privilege...
CVE-2025-36326HIGH7.5IBM Cognos Controller 11.0.0 through 11.0.1, and IBM Controller 11.1.0 through 11.1.1 could allow an attacker to obtain ...
CVE-2025-36274HIGH7.5IBM Aspera HTTP Gateway 2.0.0 through 2.3.1 stores sensitive information in clear text in easily obtainable files which ...
CVE-2025-11026HIGH7.5A vulnerability was determined in givanz Vvveb up to 1.0.7.2. Affected by this vulnerability is an unknown functionality...
CVE-2025-11019MEDIUM4.8A vulnerability has been found in Total.js CMS up to 19.9.0. This impacts an unknown function of the component Files Men...
CVE-2025-11018HIGH7.5A flaw has been found in Four-Faith Water Conservancy Informatization Platform 1.0. This affects an unknown function of ...
CVE-2025-11017MEDIUM5.5A vulnerability was detected in OGRECave Ogre up to 14.4.1. The impacted element is the function Ogre::LogManager::strea...
CVE-2025-11016MEDIUM4.3A security vulnerability has been detected in kalcaddle kodbox up to 1.61.09. The affected element is the function fileO...
CVE-2025-11015MEDIUM5.3A weakness has been identified in OGRECave Ogre up to 14.4.1. Impacted is the function STBIImageCodec::encode of the fil...
CVE-2025-9267HIGH7In Seagate Toolkit on Windows a vulnerability exists in the Toolkit Installer prior to versions 2.35.0.6 where it attemp...
CVE-2025-11060MEDIUM5.7A flaw was found in the live query subscription mechanism of the database engine. This vulnerability allows record or gu...
CVE-2025-11025MEDIUM5.3Insertion of Sensitive Information Into Sent Data vulnerability in Vimesoft Information Technologies and Software Inc. V...
CVE-2025-11014HIGH7.8A security flaw has been discovered in OGRECave Ogre up to 14.4.1. This issue affects the function STBIImageCodec::encod...
CVE-2025-11013MEDIUM5.5A vulnerability was identified in BehaviorTree up to 4.7.0. This vulnerability affects the function XMLParser::PImpl::lo...
CVE-2025-11012HIGH7.8A vulnerability was determined in BehaviorTree up to 4.7.0. This affects the function ParseScript of the file /src/scrip...
CVE-2025-11011MEDIUM5.5A vulnerability was found in BehaviorTree up to 4.7.0. Affected by this issue is the function JsonExporter::fromJson of ...
CVE-2025-11010MEDIUM5.3A vulnerability has been found in vstakhov libucl up to 0.9.2. Affected by this vulnerability is the function ucl_includ...
CVE-2025-5069MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 17.10 before 18.2.7, 18.3 before 18.3.3, and 18...
CVE-2025-11042HIGH7.5An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 before 18.2.7, 18.3 before 18.3.3, and...
CVE-2025-10868MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions from 17.4 before 18.2.7, 18.3 before 18.3.3, and 18....
CVE-2025-10544HIGH8.6Unrestricted file upload vulnerability in DocAve 6.13.2, Perimeter 1.12.3, Compliance Guardian 4.7.1, and earlier versio...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now