2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-10942HIGH8.8A vulnerability was identified in H3C Magic B3 up to 100R002. This affects the function AddMacList/EditMacList of the fi...
CVE-2025-10941HIGH8.5A vulnerability was determined in Topaz SERVCore Teller 2.14.0-RC2/2.14.1. Affected by this issue is some unknown functi...
CVE-2025-10940MEDIUM4.8A vulnerability was found in Total.js CMS 1.0.0. Affected by this vulnerability is the function layouts_save of the file...
CVE-2025-10438HIGH8.6Path Traversal: 'dir/../../filename' vulnerability in Yordam Information Technology Consulting Education and Electrical ...
CVE-2025-21056MEDIUM6.6Improper input validation in Retail Mode prior to version 5.59.4 allows self attackers to execute privileged commands on...
CVE-2025-54520HIGH8.6Improper Protection Against Voltage and Clock Glitches in FPGA devices, could allow an attacker with physical access to ...
CVE-2025-10894CRITICAL9.6Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was pub...
CVE-2025-59833HIGH7.5Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.1.0 to before 2.3.0, the API endpoint GET /api/probl...
CVE-2025-59827CRITICAL9.8Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, the /api/admin/assign-badge endpoint lacks proper acc...
CVE-2025-57324MEDIUM6.5parse is a package designed to parse JavaScript SDK. A Prototype Pollution vulnerability in the SingleInstanceStateContr...
CVE-2025-57320MEDIUM6.5json-schema-editor-visual is a package that provides jsonschema editor. A Prototype Pollution vulnerability in the setDa...
CVE-2025-57319HIGH7.5fast-redact is a package that provides do very fast object redaction. A Prototype Pollution vulnerability in the nestedR...
CVE-2025-57318HIGH7.5A Prototype Pollution vulnerability in the toCsv function of csvjson versions thru 5.1.0 allows attackers to inject prop...
CVE-2025-59828CRITICAL9.8Claude Code is an agentic coding tool. Prior to Claude Code version 1.0.39, when using Claude Code with Yarn versions 2....
CVE-2025-59824MEDIUM5.4Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to version 0.48.0, Omni Wireguard SideroLi...
CVE-2025-57329HIGH7.5web3-core-method is a package designed to creates the methods on the web3 modules. A Prototype Pollution vulnerability i...
CVE-2025-57328HIGH7.5toggle-array is a package designed to enables a property on the object at the specified index, while disabling the prope...
CVE-2025-57327HIGH7.5spmrc is a package that provides the rc manager for spm. A Prototype Pollution vulnerability in the set and config funct...
CVE-2025-57326HIGH7.5A Prototype Pollution vulnerability in the byGroupAndType function of sassdoc-extras v2.5.1 and before allows attackers ...
CVE-2025-57325HIGH7.5rollbar is a package designed to effortlessly track and debug errors in JavaScript applications. This package includes a...
CVE-2025-57323HIGH7.5mpregular is a package that provides a small program development framework based on RegularJS. A Prototype Pollution vul...
CVE-2025-57321CRITICAL9.8A Prototype Pollution vulnerability in the util-deps.addFileDepend function of magix-combine-ex versions thru 1.2.10 all...
CVE-2025-59525MEDIUM6.1Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, improper sanitization...
CVE-2025-59251HIGH7.6Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2025-57351MEDIUM6.5A prototype pollution vulnerability exists in the ts-fns package versions prior to 13.0.7, where insufficient validation...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now