2025 CVE Vulnerabilities

45,254 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-58059CRITICAL9.1Valtimo is a platform for Business Process Automation. In versions before 12.16.0.RELEASE, and from 13.0.0.RELEASE to be...
CVE-2025-58049HIGH7.5XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions fro...
CVE-2025-58048CRITICAL9.9Paymenter is a free and open-source webshop solution for hostings. Prior to version 1.2.11, the ticket attachments funct...
CVE-2025-58047HIGH7.5Volto is a React based frontend for the Plone Content Management System. In versions from 19.0.0-alpha.1 to before 19.0....
CVE-2025-57218MEDIUM5.3Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the security_5g paramet...
CVE-2025-57217MEDIUM5.3Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the Password parameter ...
CVE-2025-31971MEDIUM5.1AIML Solutions for HCL SX is vulnerable to a URL validation vulnerability.  The issue may allow attackers to launch a se...
CVE-2025-58335HIGH7.5In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54...
CVE-2025-58334HIGH8.8In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-p...
CVE-2025-57819CRITICAL9.8FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to ins...
CVE-2025-57759MEDIUM4.3Contao is an Open Source CMS. In versions starting from 5.3.0 and prior to 5.3.38 and 5.6.1, under certain conditions, b...
CVE-2025-57758MEDIUM4.3Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, the table access voter in t...
CVE-2025-57757MEDIUM5.3Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, if a news feed contains pro...
CVE-2025-57756MEDIUM5.3Contao is an Open Source CMS. In versions starting from 4.9.14 and prior to 4.13.56, 5.3.38, and 5.6.1, protected conten...
CVE-2025-31979MEDIUM5.4A File Upload Validation Bypass vulnerability has been identified in the HCL BigFix SM, where the application fails to p...
CVE-2025-31977MEDIUM6.5HCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms.  An attacker with net...
CVE-2025-31972MEDIUM6.5HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS en...
CVE-2025-57767HIGH7.5Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.15.2, 21.10.2, and 22.5.2...
CVE-2025-51643LOW2.4Meitrack T366G-L GPS Tracker devices contain an SPI flash chip (Winbond 25Q64JVSIQ) that is accessible without authentic...
CVE-2025-29364MEDIUM6.5spimsimulator spim v9.1.24 and before is vulnerable to Buffer Overflow in the READ_SYSCALL and WRITE_SYSCALL system call...
CVE-2025-25010MEDIUM6.5Incorrect authorization in Kibana can lead to privilege escalation via the built-in reporting_user role which incorrectl...
CVE-2025-8067HIGH8.5A flaw was found in the Udisks daemon, where it allows unprivileged users to create loop devices using the D-BUS system....
CVE-2025-56236MEDIUM6.1FormCms v0.5.5 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload feature. Authenticated us...
CVE-2025-55583CRITICAL9.8D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in...
CVE-2025-54995MEDIUM6.5Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now