2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-8941HIGH7.8A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local user...
CVE-2025-55163HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, N...
CVE-2025-54809HIGH8.8F5 Access for Android before version 3.1.2 which uses HTTPS does not verify the remote endpoint identity. Note: Sof...
CVE-2025-54500MEDIUM5.3An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to bre...
CVE-2025-53859MEDIUM6.3NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated at...
CVE-2025-52585HIGH8.7When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL Forward Proxy enabled and Anonymous Diff...
CVE-2025-51691MEDIUM6.1Cross-Site Scripting (XSS) vulnerability found in MarkTwo commit e3a1d3f90cce4ea9c26efcbbf3a1cbfb9dcdb298 (May 2025) all...
CVE-2025-50690MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in SpatialReference.org (OSGeo/spatialreference.org) versions prior to...
CVE-2025-50635HIGH7.5A null pointer dereference vulnerability was discovered in Netis WF2780 v2.2.35445. The vulnerability exists in the FUN_...
CVE-2025-50251CRITICAL9.1Server side request forgery (SSRF) vulnerability in makeplane plane 0.23.1 via the password recovery.
CVE-2025-48500HIGH7.3A missing file integrity check vulnerability exists on MacOS F5 VPN browser client installer that may allow a local, aut...
CVE-2025-46405HIGH8.7When Network Access is configured on a BIG-IP APM virtual server, undisclosed traffic can cause the Traffic Management M...
CVE-2025-55668MEDIUM6.5Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 thr...
CVE-2025-55160MEDIUM5.3ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2025-55154HIGH7.8ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2025-55005MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1,...
CVE-2025-55004MEDIUM4.3ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1,...
CVE-2025-54791MEDIUM5.3OMERO.web provides a web based client and plugin infrastructure. Prior to version 5.29.2, if an error occurred when rese...
CVE-2025-54382HIGH8.8Cherry Studio is a desktop client that supports for multiple LLM providers. In version 1.5.1, a remote code execution (R...
CVE-2025-54074CRITICAL9.8Cherry Studio is a desktop client that supports for multiple LLM providers. From versions 1.2.5 to 1.5.1, Cherry Studio ...
CVE-2025-52392MEDIUM5.4Soosyze CMS 2.0 allows brute-force login attacks via the /user/login endpoint due to missing rate-limiting and lockout m...
CVE-2025-52386MEDIUM5.4CycloneDX Sunshine v0.9 is vulnerable to CSV Formula Injection via a crafted JSON file
CVE-2025-32451HIGH8.8A memory corruption vulnerability exists in Foxit Reader 2025.1.0.27937 due to the use of an uninitialized pointer. A sp...
CVE-2025-8908CRITICAL9.8A vulnerability was determined in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.5.4. Affected by this ...
CVE-2025-8907HIGH7A vulnerability was found in H3C M2 NAS V100R006. Affected by this vulnerability is an unknown functionality of the comp...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now