2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-57349HIGH7.5The messageformat package, an implementation of the Unicode MessageFormat 2 specification for JavaScript, is vulnerable ...
CVE-2025-57348MEDIUM6.5The node-cube package (prior to version 5.0.0) contains a vulnerability in its handling of prototype chain initializatio...
CVE-2025-57347CRITICAL9.8A vulnerability exists in the 'dagre-d3-es' Node.js package version 7.0.9, specifically within the 'bk' module's addConf...
CVE-2025-57330HIGH7.5The web3-core-subscriptions is a package designed to manages web3 subscriptions. A Prototype Pollution vulnerability in ...
CVE-2025-55322HIGH7.3Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network.
CVE-2025-55178MEDIUM5.3Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could pote...
CVE-2025-59524MEDIUM6.1Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, the file upload flow ...
CVE-2025-59343HIGH8.7tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink...
CVE-2025-59305HIGH7.6Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated use...
CVE-2025-57354MEDIUM6.5A vulnerability exists in the 'counterpart' library for Node.js and the browser due to insufficient sanitization of user...
CVE-2025-57353MEDIUM5.3The Runtime components of messageformat package for Node.js before 3.0.2 contain a prototype pollution vulnerability. Du...
CVE-2025-57352MEDIUM5.3A vulnerability exists in the 'min-document' package prior to version 2.19.0, stemming from improper handling of namespa...
CVE-2025-57350HIGH8.6The csvtojson package, a tool for converting CSV data to JSON with customizable parsing capabilities, contains a prototy...
CVE-2025-56241HIGH7.5Aztech DSL5005EN firmware 1.00.AZ_2013-05-10 and possibly other versions allows unauthenticated attackers to change the ...
CVE-2025-52907HIGH8.8Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File Manipulation.This issue affect...
CVE-2025-52906CRITICAL9.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X60...
CVE-2025-48869HIGH7.5Horilla is a free and open source Human Resource Management System (HRMS). Unauthenticated users can access uploaded res...
CVE-2025-48867MEDIUM4.8Horilla is a free and open source Human Resource Management System (HRMS). A stored cross-site scripting (XSS) vulnerabi...
CVE-2025-20352HIGH7.7A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Softwa...
CVE-2025-20338MEDIUM6.7A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative pri...
CVE-2025-20327HIGH7.7A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to...
CVE-2025-20316MEDIUM5.3A vulnerability in the access control list (ACL) programming of Cisco IOS XE Software for Cisco Catalyst 9500X and 9600X...
CVE-2025-20315HIGH8.6A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS XE Software could allow an unau...
CVE-2025-20314MEDIUM6.7A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with level-15 privileges or an una...
CVE-2025-20313MEDIUM6.7Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileg...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now