2025 CVE Vulnerabilities

45,246 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-58442MEDIUM5.3Saleor is an e-commerce platform. Starting in version 3.21.0 and prior to version 3.21.16, requesting certain fields in ...
CVE-2025-58435MEDIUM4.1Open OnDemand is an open-source HPC portal. Prior to versions 3.1.15 and 4.0.7, noVNC interactive applications did not c...
CVE-2025-58430MEDIUM6.1listmonk is a standalone, self-hosted, newsletter and mailing list manager. In versions up to and including 1.1.0, every...
CVE-2025-58180HIGH8.8OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11....
CVE-2025-58063HIGH7.1CoreDNS is a DNS server that chains plugins. Starting in version 1.2.0 and prior to version 1.12.4, the CoreDNS etcd plu...
CVE-2025-55054MEDIUM6.1CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
CVE-2025-55053MEDIUM6.5CWE-328: Use of Weak Hash
CVE-2025-54257HIGH7.8Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Use After Free vulnerabil...
CVE-2025-54255MEDIUM4Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Violation of Secure Desig...
CVE-2025-53914HIGH7Excessive Privileges vulnerability in Calix GigaCenter ONT (Broadcom SoC modules) allows Privilege Abuse.This issue affe...
CVE-2025-53913HIGH7Excessive Privileges vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows Privilege Abuse.This issue aff...
CVE-2025-47415MEDIUM6.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CRESTRON TOUCHSCREENS x7...
CVE-2025-44594CRITICAL9.1halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/a...
CVE-2025-43786MEDIUM5.3Enumeration of ERC from object entry in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q...
CVE-2025-36125MEDIUM5.4IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This v...
CVE-2025-36011MEDIUM4.3IBM Jazz for Service Management 1.1.3.0 through 1.1.3.24 does not set the secure attribute on authorization tokens or se...
CVE-2025-34175MEDIUM6.1In pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter is directly displayed ...
CVE-2025-34174MEDIUM5.4In pfSense CE /usr/local/www/status_traffic_totals.php, the value of the start-day parameter is not ensured to be a nume...
CVE-2025-34173MEDIUM4.3In pfSense CE /usr/local/www/snort/snort_ip_reputation.php, the value of the iplist parameter is not sanitized of direct...
CVE-2025-34172MEDIUM6.1In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed af...
CVE-2025-57278HIGH8.8The LB-Link BL-CPE300M AX300 4G LTE Router firmware version BL-R8800_B10_ALK_SL_V01.01.02P42U14_06 does not implement pr...
CVE-2025-57060HIGH7.5Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the rules parameter in the dns_forward_rule_st...
CVE-2025-55730CRITICAL10XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in ...
CVE-2025-55729CRITICAL10XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in ...
CVE-2025-55728CRITICAL9.8XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now