2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-55150CRITICAL9.8Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, ...
CVE-2025-55012HIGH8.5Zed is a multiplayer code editor. Prior to version 0.197.3, in the Zed Agent Panel allowed for an AI agent to achieve Re...
CVE-2025-54992MEDIUM6.9OpenKilda is an open-source OpenFlow controller. Prior to version 1.164.0, an XML external entity (XXE) injection vulner...
CVE-2025-25235HIGH8.6Server-Side Request Forgery (SSRF) in Omnissa Secure Email Gateway (SEG) in SEG prior to 2.32 running on Windows and SEG...
CVE-2025-54878HIGH8.6CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL...
CVE-2025-40920HIGH8.6Catalyst::Authentication::Credential::HTTP versions 1.018 and earlier for Perl generate nonces using the Perl Data::UUID...
CVE-2025-8285MEDIUM5.3Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers ...
CVE-2025-7679CRITICAL9.2The ASPECT system allows users to bypass authentication. This issue affects all versions of ASPECT
CVE-2025-7677HIGH8.2A denial-of-service (DoS) attack is possible if access to the local network is provided to unauthorized users. This is d...
CVE-2025-54525HIGH7.5Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the ...
CVE-2025-54478MEDIUM5.3Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which...
CVE-2025-54463HIGH7.5Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the ...
CVE-2025-54458MEDIUM5Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows a...
CVE-2025-53910MEDIUM4Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers ...
CVE-2025-53857LOW3.7Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers ...
CVE-2025-53514MEDIUM5.9Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the ...
CVE-2025-53191Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-53190Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-53189Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-53188Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-52931HIGH7.5Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the ...
CVE-2025-51824MEDIUM6.5libcsp 2.0 is vulnerable to Buffer Overflow in the csp_usart_open() function at drivers/usart/zephyr.c.
CVE-2025-51823MEDIUM6.5libcsp 2.0 is vulnerable to Buffer Overflow in the csp_eth_init() function due to improper handling of the ifname parame...
CVE-2025-49221LOW3.7Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which...
CVE-2025-48731MEDIUM6.4Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now