2025 CVE Vulnerabilities

45,233 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-10482CRITICAL9.8A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown functio...
CVE-2025-10481HIGH8.8A security vulnerability has been detected in SourceCodester Online Student File Management System 1.0. This impacts an ...
CVE-2025-10480CRITICAL9.8A weakness has been identified in SourceCodester Online Student File Management System 1.0. This affects an unknown func...
CVE-2025-59145HIGH8.8color-name is a JSON with CSS color names. On 8 September 2025, an npm publishing account for color-name was taken over ...
CVE-2025-59056HIGH7.5FreePBX is an open-source web-based graphical user interface. In FreePBX 15, 16, and 17, malicious connections to the Ad...
CVE-2025-55211HIGH8.8FreePBX is an open-source web-based graphical user interface. From 17.0.19.11 to before 17.0.21, authenticated users of ...
CVE-2025-43799MEDIUM6.5Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 202...
CVE-2025-43798MEDIUM6.5Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35 allows a time-...
CVE-2025-10479CRITICAL9.8A security flaw has been discovered in SourceCodester Online Student File Management System 1.0. The impacted element is...
CVE-2025-10477CRITICAL9.8A vulnerability was identified in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The affec...
CVE-2025-59332HIGH8.63DAlloy is a lightWeight 3D-viewer for MediaWiki. From 1.0 through 1.8, the <3d> parser tag and the {{#3d}} parser funct...
CVE-2025-59331HIGH8.8is-arrayish checks if an object can be used like an Array. On 8 September 2025, an npm publishing account for is-arrayis...
CVE-2025-59330HIGH8.8error-ex allows error subclassing and stack customization. On 8 September 2025, an npm publishing account for error-ex w...
CVE-2025-59162HIGH8.8color-convert provides plain color conversion functions in JavaScript. On 8 September 2025, the npm publishing account f...
CVE-2025-59154MEDIUM5.9Openfire is an XMPP server licensed under the Open Source Apache License. Openfire’s SASL EXTERNAL mechanism for client ...
CVE-2025-59144HIGH8.8debug is a JavaScript debugging utility. On 8 September 2025, the npm publishing account for debug was taken over after ...
CVE-2025-59143HIGH8.8color is a Javascript color conversion and manipulation library. On 8 September 2025, the npm publishing account for col...
CVE-2025-59142HIGH8.8color-string is a parser and generator for CSS color strings. On 8 September 2025, the npm publishing account for color-...
CVE-2025-59141HIGH8.8simple-swizzle swizzles function arguments. On 8 September 2025, the npm publishing account for simple-swizzle was taken...
CVE-2025-59140HIGH8.8backlash parses collected strings with escapes. On 8 September 2025, the npm publishing account for backslash was taken ...
CVE-2025-56448MEDIUM6.8The Positron PX360BT SW REV 8 car alarm system is vulnerable to a replay attack due to a failure in implementing rolling...
CVE-2025-45091MEDIUM5.4Seafile versions 11.0.18-Pro, 12.0.10, and 12.0.10-Pro are vulnerable to a stored Cross-Site Scripting (XSS) attack. An ...
CVE-2025-10475MEDIUM5.5A weakness has been identified in SpyShelter up to 15.4.0.1015. Affected is an unknown function in the library SpyShelte...
CVE-2025-59399LOW3.1libocpp before 0.28.0 allows a denial of service (EVerest crash) because a secondary exception is thrown during error me...
CVE-2025-59398LOW3.1The OCPP implementation in libocpp before 0.26.2 allows a denial of service (EVerest crash) via JSON input larger than 2...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now