2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-3671HIGH8.8The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to Local File Inclusion in all versions u...
CVE-2025-49895MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in iThemes ServerBuddy by PluginBuddy.Com allows Object Injection.This i...
CVE-2025-55284HIGH7.5Claude Code is an agentic coding tool. Prior to version 1.0.4, it's possible to bypass the Claude Code confirmation prom...
CVE-2025-55286HIGH7.3z2d is a pure Zig 2D graphics library. z2d v0.7.0 released with a new multi-sample anti-aliasing (MSAA) method, which us...
CVE-2025-52621HIGH7.5HCL BigFix SaaS Authentication Service is vulnerable to cache poisoning.  The BigFix SaaS's HTTP responses were observe...
CVE-2025-52620MEDIUM5.4HCL BigFix SaaS Authentication Service is affected by a Cross-Site Scripting (XSS) vulnerability. The image upload func...
CVE-2025-52619MEDIUM5.3HCL BigFix SaaS Authentication Service is affected by a sensitive information disclosure. Under certain conditions, err...
CVE-2025-52618CRITICAL9.8HCL BigFix SaaS Authentication Service is affected by a SQL injection vulnerability. The vulnerability allows potential...
CVE-2025-43201MEDIUM6.2This issue was addressed with improved checks. This issue is fixed in Apple Music Classical 2.3 for Android. An app may ...
CVE-2025-8959HIGH7.5HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized rea...
CVE-2025-44201Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2025-36088MEDIUM5.4IBM TS4500 1.11.0.0-D00, 1.11.0.1-C00, 1.11.0.2-C00, and 1.10.00-F00 web GUI is vulnerable to cross-site scripting. This...
CVE-2025-43490HIGH8.4A potential security vulnerability has been identified in the HPAudioAnalytics service included in the HP Hotkey Support...
CVE-2025-55285LOW2.6@backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. Prior to version 2.1.1...
CVE-2025-9060CRITICAL9.1A vulnerability has been found in the  MSoft MFlash application that allows execution of arbitrary code on the server...
CVE-2025-8996MEDIUM4.3Missing Authorization vulnerability in Drupal Layout Builder Advanced Permissions allows Forceful Browsing.This issue af...
CVE-2025-8995CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authenticati...
CVE-2025-8675HIGH8.8Server-Side Request Forgery (SSRF) vulnerability in Drupal AI SEO Link Advisor allows Server Side Request Forgery.This i...
CVE-2025-8362MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal GoogleTag M...
CVE-2025-8361HIGH7.6Missing Authorization vulnerability in Drupal Config Pages allows Forceful Browsing. This issue affects Config Pages: f...
CVE-2025-8092HIGH7.6Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Con...
CVE-2025-7961MEDIUM6.9Improper Control of Generation of Code ('Code Injection') vulnerability in Wulkano KAP on MacOS allows TCC Bypass.This i...
CVE-2025-8066MEDIUM4.8URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Bunkerity Bunker Web on Linux allows Phishing.This ...
CVE-2025-55207MEDIUM5.5Astro is a web framework for content-driven websites. Following CVE-2025-54793 there's still an Open Redirect vulnerabil...
CVE-2025-49898HIGH7.6Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xolluteon Dropshix...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now