2025 CVE Vulnerabilities

45,233 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-54237MEDIUM5.5Substance3D - Stager versions 3.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to m...
CVE-2025-10572Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-9199. Reason: This candidate is a r...
CVE-2025-59336MEDIUM6.9Luanox is a module host for Lua packages. Prior to 0.1.1, a file traversal vulnerability can cause potential denial of s...
CVE-2025-59334HIGH8.8Linkr is a lightweight file delivery system that downloads files from a webserver. Linkr versions through 2.0.0 do not v...
CVE-2025-59161LOW2.7Element Web is a Matrix web client built using the Matrix React SDK. Element Web and Element Desktop before version 1.11...
CVE-2025-59160LOW2.7Matrix JavaScript SDK is a Matrix Client-Server SDK for JavaScript and TypeScript. matrix-js-sdk before 38.2.0 has insuf...
CVE-2025-59050HIGH7.8Greenshot is an open source Windows screenshot utility. Greenshot 1.3.300 and earlier deserializes attacker-controlled d...
CVE-2025-58174MEDIUM4.6LDAP Account Manager (LAM) is a webfrontend for managing entries stored in an LDAP directory. LAM before 9.3 allows stor...
CVE-2025-43801HIGH7.5Unchecked input for loop condition vulnerability in XML-RPC in Liferay Portal 7.4.0 through 7.4.3.111, and older unsuppo...
CVE-2025-10492CRITICAL9.8A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied...
CVE-2025-58749MEDIUM5.3WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. In WAMR versions prior to 2.4.2...
CVE-2025-30075LOW2.2In Alludo MindManager before 25.0.208 on Windows, attackers could potentially execute code as other local users on the s...
CVE-2025-8894HIGH7.8A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerabi...
CVE-2025-8893HIGH7.8A maliciously crafted PDF file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerab...
CVE-2025-59333HIGH8.1The mcp-database-server (MCP Server) 1.1.0 and earlier, as distributed via the npm package @executeautomation/database-s...
CVE-2025-59270LOW3.1psPAS PowerShell module does not explicitly enforce TLS 1.2 within the 'Get-PASSAMLResponse' function during the SAML au...
CVE-2025-57145MEDIUM5.4A cross-site scripting (XSS) vulnerability exists in the search-autootaxi.php endpoint of the ATSMS web application. The...
CVE-2025-56295HIGH7.3code-projects Computer Laboratory System 1.0 has a file upload vulnerability. Staff can upload malicious files by upload...
CVE-2025-56293MEDIUM5.4code-projects Human Resource Integrated System 1.0 is vulnerable to Cross Site Scripting (XSS) in the Add Child Informat...
CVE-2025-56289MEDIUM5.4code-projects Document Management System 1.0 has a Cross Site Scripting (XSS) vulnerability, where attackers can leak ad...
CVE-2025-56280MEDIUM5.4code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the area where users submit...
CVE-2025-4953HIGH7.4A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman...
CVE-2025-41243CRITICAL10Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application shoul...
CVE-2025-36244MEDIUM5.5IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, could allow a local use...
CVE-2025-8276MEDIUM4.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escapi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now