2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-24469Rejected reason: Not used
CVE-2025-24468Rejected reason: Not used
CVE-2025-22864Rejected reason: Not used
CVE-2025-22863Rejected reason: Not used
CVE-2025-22861Rejected reason: Not used
CVE-2025-22860Rejected reason: Not used
CVE-2025-43770MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024...
CVE-2025-8193Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-9356HIGH8.8A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.0...
CVE-2025-9355HIGH8.8A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002...
CVE-2025-55455LOW3.5DooTask v1.0.51 was dicovered to contain an authenticated arbitrary download vulnerability via the component /msg/sendte...
CVE-2025-52451HIGH8.5Improper Input Validation vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - create-data-source-...
CVE-2025-52450MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Serve...
CVE-2025-4609CRITICAL9.6Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136.0.7103.113 allow...
CVE-2025-43761MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024...
CVE-2025-26498HIGH7.3Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (establish-...
CVE-2025-26497HIGH7.3Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Edito...
CVE-2025-26496CRITICAL9.3Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Deskto...
CVE-2025-57801CRITICAL9.1gnark is a zero-knowledge proof system framework. In versions prior to 0.14.0, the Verify function in eddsa.go and ecdsa...
CVE-2025-6791HIGH8.8In the monitoring event logs page, it is possible to alter the http request to insert a reflect payload in the DB. Cause...
CVE-2025-55454HIGH8.8An authenticated arbitrary file upload vulnerability in the component /msg/sendfiles of DooTask v1.0.51 allows attackers...
CVE-2025-54813HIGH7.5Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using JSONLayout, not all payload bytes a...
CVE-2025-54812MEDIUM5.4Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using HTMLLayout, logger names are not p...
CVE-2025-51092CRITICAL9.8The LogIn-SignUp project by VishnuSivadasVS is vulnerable to SQL Injection due to unsafe construction of SQL queries in ...
CVE-2025-50859MEDIUM6.1Reflected Cross-Site Scripting in the Change Template function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows aut...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now