2025 CVE Vulnerabilities

45,251 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-58751MEDIUM5.3Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting w...
CVE-2025-58746CRITICAL9The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashbo...
CVE-2025-58745HIGH8.8WeGIA is a Web manager for charitable institutions. The fix for CVE-2025-22133 was not enough to remediate the arbitrary...
CVE-2025-58454HIGH8.2WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in WeGIA versions 3.4.1...
CVE-2025-58453HIGH8.2WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in WeGIA versions 3.4.1...
CVE-2025-58452MEDIUM6.1WeGIA is a Web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified ...
CVE-2025-1761HIGH7.5IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated me...
CVE-2025-10111CRITICAL9.8A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is a...
CVE-2025-10110HIGH8.8A vulnerability was identified in ChanCMS up to 3.3.1. Impacted is an unknown function of the file /search/. The manipul...
CVE-2025-10109CRITICAL9.8A vulnerability was determined in Campcodes Online Loan Management System 1.0. This issue affects some unknown processin...
CVE-2025-58451HIGH8.7Cattown is a JavaScript markdown parser. Versions prior to 1.0.2 used regular expressions with inefficient, potentially ...
CVE-2025-58450CRITICAL9.3pREST (PostgreSQL REST), is an API that delivers an application on top of a Postgres database. SQL injection is possible...
CVE-2025-58449HIGH8.7Maho is a free and open source ecommerce platform. In Maho prior to 25.9.0, an authenticated staff user with access to t...
CVE-2025-58444HIGH8.6The MCP inspector is a developer tool for testing and debugging MCP servers. A cross-site scripting issue was reported i...
CVE-2025-58365HIGH8.7The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Prior to version 9.14, th...
CVE-2025-57817HIGH7.2Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the OAuth client creation and update endp...
CVE-2025-57816HIGH7.5Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Webserver API's built-in IP-bas...
CVE-2025-57815MEDIUM6.5Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Admin UI login endpoint relies ...
CVE-2025-57766MEDIUM4.8Fides is an open-source privacy engineering platform. Prior to version 2.69.1, admin UI user password changes in Fides d...
CVE-2025-10108CRITICAL9.8A vulnerability was found in Campcodes Online Loan Management System 1.0. This vulnerability affects unknown code of the...
CVE-2025-10106HIGH8.8A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.1. This affects an unknown part of the file /cms/collec...
CVE-2025-52288HIGH7.5Assertion failure in function ngap_build_downlink_nas_transport in file src/amf/ngap-build.c, the Access and Mobility Ma...
CVE-2025-10105HIGH8.8A flaw has been found in yanyutao0402 ChanCMS up to 3.3.1. Affected by this issue is some unknown functionality of the f...
CVE-2025-54994CRITICAL9.3@akoskm/create-mcp-server-stdio is an MCP server starter kit that uses the StdioServerTransport. Prior to version 0.0.13...
CVE-2025-53838MEDIUM5.4LinkAce is a self-hosted archive to collect website links. A stored cross-site scripting (XSS) vulnerability was discove...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now