2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-54234LOW2.7ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerabil...
CVE-2025-3639LOW2Liferay Portal 7.3.0 through 7.4.3.132, and Liferay DXP 2025.Q1 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q3....
CVE-2025-54421MEDIUM5.4NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerab...
CVE-2025-54118MEDIUM5.3NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Sensitive information disclosure in...
CVE-2025-54117MEDIUM5.4NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerab...
CVE-2025-4962HIGH7.7An Insecure Direct Object Reference (IDOR) vulnerability was identified in the `POST /v1/templates` endpoint of the Luna...
CVE-2025-43732LOW2.7Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.10, 2024.Q4.0 through 2024.Q4.7, 2024....
CVE-2025-36120HIGH8.8IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH s...
CVE-2025-33100HIGH7.5IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cryptographic key, whi...
CVE-2025-33090HIGH7.5IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to cause a denial of service using a specially cr...
CVE-2025-27909CRITICAL9.8IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carr...
CVE-2025-1759HIGH7.5IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated me...
CVE-2025-43733MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q1.0 through ...
CVE-2025-47206HIGH8.1An out-of-bounds write vulnerability has been reported to affect File Station 5. If a remote attacker gains a user accou...
CVE-2025-41242MEDIUM5.9Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnerability” when deployed on a non-compliant...
CVE-2025-5296HIGH7.3CWE-59: Improper Link Resolution Before File Access ('Link Following') vulnerability exists that could cause arbitrary ...
CVE-2025-6625HIGH8.7CWE-20: Improper Input Validation vulnerability exists that could cause a Denial Of Service when specific crafted FTP co...
CVE-2025-57703MEDIUM6.1DIAEnergie - Reflected Cross-site Scripting
CVE-2025-57702MEDIUM6.1DIAEnergie - Reflected Cross-site Scripting
CVE-2025-57701MEDIUM6.1DIAEnergie - Reflected Cross-site Scripting
CVE-2025-57700MEDIUM6.1DIAEnergie - Stored Cross-site Scripting
CVE-2025-9109LOW3.7A security flaw has been discovered in Portabilis i-Diario up to 1.5.0. Affected by this vulnerability is an unknown fun...
CVE-2025-9108MEDIUM4.3Affected is an unknown function of the component Login Page. The manipulation leads to improper restriction of rendered ...
CVE-2025-9107MEDIUM6.1A vulnerability was determined in Portabilis i-Diario up to 1.5.0. This impacts an unknown function of the file /alunos/...
CVE-2025-9106MEDIUM5.4A vulnerability was found in Portabilis i-Diario up to 1.5.0. This affects an unknown function of the file /planos-de-en...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now