2025 CVE Vulnerabilities

45,233 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-8057MEDIUM6.5Authorization Bypass Through User-Controlled Key, Externally Controlled Reference to a Resource in Another Sphere, Impro...
CVE-2025-57119CRITICAL9.8An issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php comp...
CVE-2025-56276MEDIUM5.4code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the registration function. ...
CVE-2025-52044HIGH7.5In Frappe ERPNext v15.57.5, the function get_stock_balance() at erpnext/stock/utils.py is vulnerable to SQL Injection, w...
CVE-2025-44034HIGH8SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute arbitrary code via the alph par...
CVE-2025-39836HIGH7.8In the Linux kernel, the following vulnerability has been resolved: efi: stmm: Fix incorrect buffer allocation method ...
CVE-2025-39835HIGH7.8In the Linux kernel, the following vulnerability has been resolved: xfs: do not propagate ENODATA disk errors into xatt...
CVE-2025-39834MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/mlx5: HWS, Fix memory leak in hws_action_get_sh...
CVE-2025-39833MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mISDN: hfcpci: Fix warning when deleting uninitiali...
CVE-2025-39832MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix lockdep assertion on sync reset unloa...
CVE-2025-39831MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fbnic: Move phylink resume out of service_task and ...
CVE-2025-39830MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/mlx5: HWS, Fix memory leak in hws_pool_buddy_in...
CVE-2025-7355MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in Beefull Energy Technologies Beefull App allows Exploit...
CVE-2025-55834MEDIUM6.1A Cross Site Scripting vulnerability in JeeWMS v.3.7 and before allows a remote attacker to obtain sensitive information...
CVE-2025-55118HIGH8.9Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured. The issu...
CVE-2025-55117MEDIUM6.3A stack-based buffer overflow can be remotely triggered when formatting an error message in the Control-M/Agent when SSL...
CVE-2025-55116CRITICAL9.3A buffer overflow in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the sys...
CVE-2025-55115CRITICAL9.3A path traversal in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the syst...
CVE-2025-55114MEDIUM6.9The improper order of AUTHORIZED_CTM_IP validation in the Control-M/Agent, where the Control-M/Server IP address is vali...
CVE-2025-55113CRITICAL10If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support Cont...
CVE-2025-55112HIGH7.6Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 (and potentially earlier unsupported versions) that are configu...
CVE-2025-55111MEDIUM5.7Certain files with overly permissive permissions were identified in the out-of-support Control-M/Agent versions 9.0.18 t...
CVE-2025-55110MEDIUM5.7Control-M/Agents use a kdb or PKCS#12 keystore by default, and the default keystore password is well known and documente...
CVE-2025-55109CRITICAL9.5An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potent...
CVE-2025-39829MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: trace/fgraph: Fix the warning caused by missing unr...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now