2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-11382Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-11381Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-50857CRITICAL9.8ZenTaoPMS v18.11 through v21.6.beta is vulnerable to Directory Traversal in /module/ai/control.php. This allows attacker...
CVE-2025-71057HIGH8.2Improper session management in D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME_1.00 allows attackers to execute a s...
CVE-2025-56605MEDIUM5.4A reflected Cross-Site Scripting (XSS) vulnerability exists in the register.php backend script of PuneethReddyHC Event M...
CVE-2025-14343HIGH7.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dokuzsoft T...
CVE-2025-64999MEDIUM5.4Improper neutralization of input in Checkmk versions 2.4.0 before 2.4.0p22, and 2.3.0 before 2.3.0p43 allows an attacker...
CVE-2025-14511HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.2 before 18.7.5, 18.8 before 18.8.5, and 1...
CVE-2025-3525MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.7.5, 18.8 before 18.8.5, and 18...
CVE-2025-14103MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.7.5, 18.8 before 18.8.5, and 1...
CVE-2025-69771CRITICAL9.6Cross-Site Scripting (XSS) vulnerability in the subtitle loading function of the asbplayer Chrome Extension version 1.14...
CVE-2025-50180HIGH7.5esm.sh is a no-build content delivery network (CDN) for web development. In version 136, esm.sh is vulnerable to a full-...
CVE-2025-1242CRITICAL9.3The administrative credentials can be extracted through application API responses, mobile application reverse engineerin...
CVE-2025-67860LOW3.8A vulnerability has been identified in the NeuVector scanner where the scanner process accepts registry and controller c...
CVE-2025-67601MEDIUM4.8A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -ski...
CVE-2025-62878CRITICAL9.9A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the hos...
CVE-2025-14742MEDIUM4.3The WP Recipe Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check ...
CVE-2025-11563MEDIUM4.6URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current ...
CVE-2025-0976HIGH7.5Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager.This i...
CVE-2025-5781MEDIUM5.2Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitac...
CVE-2025-69231MEDIUM5.4OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio...
CVE-2025-68277MEDIUM5OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio...
CVE-2025-67752HIGH8.1OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio...
CVE-2025-67491MEDIUM5.4OpenEMR is a free and open source electronic health records and medical practice management application. Versions 5.0.0....
CVE-2025-46320MEDIUM6.1A cross-site scripting (XSS) vulnerability in a FileMaker WebDirect custom homepage could lead to unauthorized access an...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now