2025 CVE Vulnerabilities

45,254 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-55212HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2025-52184MEDIUM6.1Cross Site Scripting vulnerability in Helpy.io v.2.8.0 allows a remote attacker to escalate privileges via the New Topic...
CVE-2025-50974MEDIUM6.5The Calamaris log exporter CGI (/cgi-bin/logs.cgi/calamaris.dat) in IPFire 2.29 does not properly sanitize user-supplied...
CVE-2025-36729HIGH7.2A non-primary administrator user with admin rights to the web interface but without shell access permissions can display...
CVE-2025-2697CRITICAL9.3IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to conduct phishing attacks, using an open...
CVE-2025-1994HIGH7.8IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a local user to execute arbitrary code on the system due t...
CVE-2025-1494MEDIUM6.1IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to hijack the clicking action of the victim....
CVE-2025-57813MEDIUM5.9traQ is a messenger application built for Digital Creators Club traP. Prior to version 3.25.0, a vulnerability exists wh...
CVE-2025-57810HIGH7.5jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.2, user control of the first argument of the addImage me...
CVE-2025-56432MEDIUM6.1A cross-site scripting (XSS) vulnerability exists in Nagios XI 2024R2. The vulnerability allows remote attackers to exec...
CVE-2025-6366HIGH8.8The Event List plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.0.4. T...
CVE-2025-52219MEDIUM6.5SelectZero SelectZero Data Observability Platform before 2025.5.2 contains an Open Redirect vulnerability. Legacy UI fie...
CVE-2025-52218HIGH7.5SelectZero Data Observability Platform before 2025.5.2 is vulnerable to Content Spoofing / Text Injection. Improper sani...
CVE-2025-52217MEDIUM5.4SelectZero Data Observability Platform before 2025.5.2 is vulnerable to HTML Injection. Legacy UI fields improperly hand...
CVE-2025-52037MEDIUM6.1A vulnerability has been found in NotesCMS and classified as medium. Affected by this vulnerability is the page /index.p...
CVE-2025-52036MEDIUM6.1A vulnerability has been found in NotesCMS and classified as medium. Affected by this vulnerability is the page /index.p...
CVE-2025-52035MEDIUM6.1A vulnerability in NotesCMS and specifically in the page /index.php?route=notes. The manipulation of the title of the se...
CVE-2025-25737MEDIUM6.8Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were disco...
CVE-2025-25736MEDIUM6.8Kapsch TrafficCom RIS-9260 RSU LEO v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to contain Android ...
CVE-2025-25735MEDIUM4.6Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were disco...
CVE-2025-25734MEDIUM6.8Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 was discov...
CVE-2025-25733LOW3.5Incorrect access control in the SPI Flash Chip of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829...
CVE-2025-25732MEDIUM6.8Incorrect access control in the EEPROM component of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.8...
CVE-2025-9483HIGH8.8A flaw has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1...
CVE-2025-9482HIGH8.8A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now