2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-54136HIGH8.8Cursor is a code editor built for programming with AI. In versions 1.2.4 and below, attackers can achieve remote and per...
CVE-2025-54133CRITICAL9.6Cursor is a code editor built for programming with AI. In versions 1.17 through 1.2, there is a UI information disclosur...
CVE-2025-54792MEDIUM6.8LocalSend is an open-source app to securely share files and messages with nearby devices over local networks without nee...
CVE-2025-54424CRITICAL9.81Panel is a web interface and MCP Server that manages websites, files, containers, databases, and LLMs on a Linux server...
CVE-2025-54132HIGH7.5Cursor is a code editor built for programming with AI. In versions below 1.3, Mermaid (which is used to render diagrams)...
CVE-2025-54131HIGH8.8Cursor is a code editor built for programming with AI. In versions below 1.3, an attacker can bypass the allow list in a...
CVE-2025-8480HIGH8Alpine iLX-507 Command Injection Remote Code Execution. This vulnerability allows network-adjacent attackers to execute ...
CVE-2025-8477HIGH7.4Alpine iLX-507 vCard Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows ...
CVE-2025-8476HIGH8Alpine iLX-507 TIDAL Improper Certificate Validation Vulnerability. This vulnerability allows network-adjacent attackers...
CVE-2025-8475HIGH7.4Alpine iLX-507 AVRCP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-...
CVE-2025-8474MEDIUM6.8Alpine iLX-507 CarPlay Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows physically pr...
CVE-2025-8473MEDIUM6.6Alpine iLX-507 UPDM_wstpCBCUpdStart Command Injection Vulnerability. This vulnerability allows physically present attack...
CVE-2025-8472HIGH7.4Alpine iLX-507 vCard Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows ...
CVE-2025-6037MEDIUM6.8Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when con...
CVE-2025-6015MEDIUM5.7Vault and Vault Enterprise’s (“Vault”) login MFA rate limits could be bypassed and TOTP tokens could be reused. Fixed in...
CVE-2025-6014MEDIUM6.5Vault and Vault Enterprise’s (“Vault”) TOTP Secrets Engine code validation endpoint is susceptible to code reuse within ...
CVE-2025-6011LOW3.7A timing side channel in Vault and Vault Enterprise’s (“Vault”) userpass auth method allowed an attacker to distinguish ...
CVE-2025-6004MEDIUM5.3Vault and Vault Enterprise’s (“Vault”) user lockout feature could be bypassed for Userpass and LDAP authentication metho...
CVE-2025-6000CRITICAL9.1A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution o...
CVE-2025-5999HIGH7.2A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or...
CVE-2025-54595HIGH7.3Pearcleaner is a free, source-available and fair-code licensed mac app cleaner. The PearcleanerHelper is a privileged he...
CVE-2025-54593HIGH7.2FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.1 and below, an authenticated administrator user can ...
CVE-2025-54590MEDIUM6.9webfinger.js is a TypeScript-based WebFinger client that runs in both browsers and Node.js environments. In versions 2.8...
CVE-2025-54574CRITICAL9.8Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possi...
CVE-2025-54564HIGH7.8uploadsm in ChargePoint Home Flex 5.5.4.13 does not validate a user-controlled string for bz2 decompression, which allow...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now