2025 CVE Vulnerabilities

45,251 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-40930HIGH7.5JSON::SIMD before version 1.07 and earlier for Perl has an integer buffer overflow causing a segfault when parsing craft...
CVE-2025-40929MEDIUM5.6Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSO...
CVE-2025-40928HIGH7.5JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabl...
CVE-2025-36855HIGH8.8A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. P...
CVE-2025-36854HIGH8.1A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL ASP.NET when closing an HTTP/3 stream whi...
CVE-2025-36853HIGH7.5A vulnerability (CVE-2025-21172) exists in msdia140.dll due to integer overflow and heap-based overflow. Per CWE-122: ...
CVE-2025-22956CRITICAL9.8OPSI before 4.3 allows any client to retrieve any ProductPropertyState, including those of other clients. This can lead ...
CVE-2025-3212MEDIUM5.3Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge...
CVE-2025-40642MEDIUM5.1Reflected Cross-Site Scripting (XSS) vulnerability in WebWork, which allows remote attackers to execute arbitrary code t...
CVE-2025-40641MEDIUM5.1Cross-site Scripting (XSS) vulnerability stored in Multi-Purpose Inventory Management System, consisting of a stored XSS...
CVE-2025-10093HIGH7.5A vulnerability was identified in D-Link DIR-852 up to 1.00CN B09. Affected by this vulnerability is the function phpcgi...
CVE-2025-10092CRITICAL9.8A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectman...
CVE-2025-5993CRITICAL9.2ITCube CRM in versions from 2023.2 through 2025.2 is vulnerable to path traversal. Unauthenticated remote attacker is ab...
CVE-2025-10091CRITICAL9.8A vulnerability has been found in Jinher OA up to 1.2. This affects an unknown function of the file /c6/Jhsoft.Web.proje...
CVE-2025-10090CRITICAL9.8A flaw has been found in Jinher OA up to 1.2. The impacted element is an unknown function of the file /C6/Jhsoft.Web.dep...
CVE-2025-58782MEDIUM6.5Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue...
CVE-2025-41708HIGH7.4Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface. An unauthenticated attacke...
CVE-2025-41682HIGH8.8An authenticated, low-privileged attacker can obtain credentials stored on the charge controller including the manufactu...
CVE-2025-41664HIGH7.5A low-privileged remote attacker could gain unauthorized access to critical resources, such as firmware and certificates...
CVE-2025-10088MEDIUM5.4A vulnerability was detected in SourceCodester Time Tracker 1.0. The affected element is an unknown function of the file...
CVE-2025-10087HIGH7.2A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0. Impacted is an unknow...
CVE-2025-8085HIGH8.6The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoi...
CVE-2025-10086MEDIUM6.3A weakness has been identified in fuyang_lipengjun platform 1.0.0. This issue affects the function queryAll of the file ...
CVE-2025-10085HIGH8.8A security flaw has been discovered in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects u...
CVE-2025-58422LOW3.1RICOH Streamline NX versions 3.5.1 to 24R3 are vulnerable to tampering with operation history. If an attacker can perfor...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now