2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-45313MEDIUM6.1A cross-site scripting (XSS) vulnerability in the /tasks endpoint of hortusfox-web v4.4 allows attackers to execute arbi...
CVE-2025-43989MEDIUM6.5The /goform/formJsonAjaxReq POST endpoint of Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLICv3.4.2731.16.43 devices mishandl...
CVE-2025-8921CRITICAL9.8A vulnerability has been found in code-projects Job Diary 1.0. Affected by this issue is some unknown functionality of t...
CVE-2025-8920MEDIUM5.4A vulnerability was identified in Portabilis i-Diario 1.6. Affected by this vulnerability is an unknown functionality of...
CVE-2025-8919MEDIUM4.8A vulnerability was determined in Portabilis i-Diario up to 1.6. Affected is an unknown function of the file /objetivos-...
CVE-2025-8904CRITICAL9Amazon EMR Secret Agent creates a keytab file containing Kerberos credentials. This file is stored in the /tmp/ director...
CVE-2025-8770MEDIUM6.5An issue has been discovered in GitLab EE affecting all versions from 18.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18...
CVE-2025-8754HIGH8.7Missing Authentication for Critical Function vulnerability in ABB ABB AbilityTM zenon.This issue affects ABB AbilityTM z...
CVE-2025-7739MEDIUM5.4An issue has been discovered in GitLab CE/EE affecting all versions from 18.2 before 18.2.2 that, under certain conditio...
CVE-2025-7734MEDIUM5.4An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 before 18.0.6, 18.1 before 18.1.4 and 18.2...
CVE-2025-6186MEDIUM5.4An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.1.4, and 18.2 before 18.2.2 that...
CVE-2025-5819MEDIUM5An issue has been discovered in GitLab CE/EE affecting all versions from 15.7 before 18.0.6, 18.1 before 18.1.4, and 18....
CVE-2025-50946MEDIUM6.5OS Command Injection in Olivetin 2025.4.22 Custom Themes via the ParseRequestURI function in service/internal/executor/a...
CVE-2025-50617HIGH7.5A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_0046ed68 function of the cgite...
CVE-2025-50616HIGH7.5A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_0046f984 function of the cgite...
CVE-2025-50615HIGH7.5A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00470c50 function of the cgite...
CVE-2025-45317MEDIUM6.5A zip slip vulnerability in the /modules/ImportModule.php component of hortusfox-web v4.4 allows attackers to execute ar...
CVE-2025-45316MEDIUM6.1A cross-site scripting (XSS) vulnerability in the TextBlockModule.php component of hortusfox-web v4.4 allows attackers t...
CVE-2025-45315MEDIUM5.4A cross-site scripting (XSS) vulnerability in the /controller/admin.php endpoint of hortusfox-web v4.4 allows attackers ...
CVE-2025-45314MEDIUM6.1A cross-site scripting (XSS) vulnerability in the /Calendar endpoint of hortusfox-web v4.4 allows attackers to execute a...
CVE-2025-2937MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 13.2 before 18.0.6, 18.1 before 18.1.4, and 18....
CVE-2025-2614MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 18.0.6, 18.1 before 18.1.4, and 18....
CVE-2025-2498MEDIUM4.3An improper access control in Gitlab EE affecting all versions from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2...
CVE-2025-23306HIGH7.8NVIDIA Megatron-LM for all platforms contains a vulnerability in the megatron/training/ arguments.py component where an ...
CVE-2025-23305HIGH7.8NVIDIA Megatron-LM for all platforms contains a vulnerability in the tools component, where an attacker may exploit a co...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now