2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-20220MEDIUM6A vulnerability in the CLI of Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat De...
CVE-2025-20219MEDIUM5.3A vulnerability in the implementation of access control rules for loopback interfaces in Cisco Secure Firewall Adaptive ...
CVE-2025-20218MEDIUM4.9A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could al...
CVE-2025-20217HIGH8.6A vulnerability in the packet inspection functionality of the Snort 3 Detection Engine of Cisco Secure Firewall Threat D...
CVE-2025-20148HIGH8.5A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could al...
CVE-2025-20136HIGH8.6A vulnerability in the function that performs IPv4 and IPv6 Network Address Translation (NAT) DNS inspection for Cisco S...
CVE-2025-20135MEDIUM4.3A vulnerability in the DHCP client functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and...
CVE-2025-20134HIGH8.6A vulnerability in the certificate processing of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Ci...
CVE-2025-20133HIGH8.6A vulnerability in the management and VPN web servers of the Remote Access SSL VPN feature of Cisco Secure Firewall ASA ...
CVE-2025-20127HIGH7.7A vulnerability in the TLS 1.3 implementation for a specific cipher for Cisco Secure Firewall Adaptive Security Applianc...
CVE-2025-8967CRITICAL9.8A vulnerability was determined in itsourcecode Online Tour and Travel Management System 1.0. Affected is an unknown func...
CVE-2025-8966CRITICAL9.8A vulnerability was found in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown ...
CVE-2025-8965HIGH8.8A vulnerability has been found in linlinjava litemall up to 1.8.0. This vulnerability affects the function create of the...
CVE-2025-54867HIGH7Youki is a container runtime written in Rust. Prior to version 0.5.5, if /proc and /sys in the rootfs are symbolic links...
CVE-2025-54409MEDIUM5.5AIDE is an advanced intrusion detection environment. From versions 0.13 to 0.19.1, there is a null pointer dereference v...
CVE-2025-54389MEDIUM5.5AIDE is an advanced intrusion detection environment. Prior to version 0.19.2, there is an improper output neutralization...
CVE-2025-53631MEDIUM5.4flaskBlog is a blog app built with Flask. In versions 2.8.1 and prior, improper sanitization of postContent when submitt...
CVE-2025-50518CRITICAL9.8A use-after-free vulnerability exists in the coap_delete_pdu_lkd function within coap_pdu.c of the libcoap library. This...
CVE-2025-36047HIGH7.5IBM WebSphere Application Server Liberty 18.0.0.2 through 25.0.0.8 is vulnerable to a denial of service, caused by sendi...
CVE-2025-33142HIGH7.5IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS connections.
CVE-2025-9042HIGH8.7A security issue exists due to improper handling of CIP Class 32’s request when a module is inhibited on the 5094-IY8 de...
CVE-2025-9041HIGH8.7A security issue exists due to improper handling of CIP Class 32’s request when a module is inhibited on the 5094-IF8 de...
CVE-2025-8964HIGH7.8A vulnerability was identified in code-projects Hostel Management System 1.0. This affects an unknown part of the file h...
CVE-2025-8962HIGH7.8A vulnerability was found in code-projects Hostel Management System 1.0. Affected by this vulnerability is an unknown fu...
CVE-2025-8876HIGH8.8Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: be...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now