2025 CVE Vulnerabilities

45,233 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-36082LOW3.3IBM OpenPages 9.0 and 9.1 allows web page cache to be stored locally which can be read by another user on the system.
CVE-2025-10491HIGH7.8The MongoDB Windows installation MSI may leave ACLs unset on custom installation directories allowing a local attacker t...
CVE-2025-8396MEDIUM6.9Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server o...
CVE-2025-6202HIGH7.1Vulnerability in SK Hynix DDR5 on x86 allows a local attacker to trigger Rowhammer bit flips impacting the Hardware Inte...
CVE-2025-52053CRITICAL9.8TOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_417D74 functio...
CVE-2025-10459CRITICAL9.8A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of ...
CVE-2025-59377CRITICAL9.8feiskyer mcp-kubernetes-server through 0.1.11 allows OS command injection, even in read-only mode, via /mcp/kubectl beca...
CVE-2025-59376MEDIUM5.3feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-writ...
CVE-2025-56710HIGH7.3A Cross-Site Request Forgery (CSRF) vulnerability was identified in the Profile Page of the PHPGurukul Student-Result-Ma...
CVE-2025-50944HIGH8.8An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes ...
CVE-2025-50110HIGH8.8An issue was discovered in the method push.lite.avtech.com.AvtechLib.GetHttpsResponse in AVTECH EagleEyes Lite 2.0.0, th...
CVE-2025-46408CRITICAL9.8An issue was discovered in the methods push.lite.avtech.com.AvtechLib.GetHttpsResponse and push.lite.avtech.com.Push_Htt...
CVE-2025-10448CRITICAL9.8A flaw has been found in Campcodes Online Job Finder System 1.0. This affects an unknown function of the file /index.php...
CVE-2025-10447CRITICAL9.8A vulnerability was detected in Campcodes Online Job Finder System 1.0. The impacted element is an unknown function of t...
CVE-2025-3025HIGH7.3Elevation of Privileges in the cleaning feature of Gen Digital CCleaner version 6.33.11465 on Windows allows a local use...
CVE-2025-39804HIGH7.8In the Linux kernel, the following vulnerability has been resolved: lib/crypto: arm64/poly1305: Fix register corruption...
CVE-2025-39803HIGH7.8In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Remove WARN_ON_ONCE() call from uf...
CVE-2025-39802HIGH7.8In the Linux kernel, the following vulnerability has been resolved: lib/crypto: arm/poly1305: Fix register corruption i...
CVE-2025-39801MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: Remove WARN_ON for device endpoint comma...
CVE-2025-39800MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: abort transaction on unexpected eb generatio...
CVE-2025-10446CRITICAL9.8A security vulnerability has been detected in Campcodes Computer Sales and Inventory System 1.0. The affected element is...
CVE-2025-10445CRITICAL9.8A weakness has been identified in Campcodes Computer Sales and Inventory System 1.0. Impacted is an unknown function of ...
CVE-2025-59361CRITICAL9.8The cleanIptables mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-20...
CVE-2025-59360CRITICAL9.8The killProcesses mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-20...
CVE-2025-59359CRITICAL9.8The cleanTcs mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now