2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-30480MEDIUM6.5Dell PowerProtect Data Manager, versions prior to 19.19, contain(s) an Improper Input Validation vulnerability in PowerP...
CVE-2025-30105MEDIUM5.5Dell XtremIO, version(s) 6.4.0-22, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low p...
CVE-2025-26332MEDIUM5.5TechAdvisor versions 2.6 through 3.37-30 for Dell XtremIO X2, contain(s) an Insertion of Sensitive Information into Log ...
CVE-2025-45620HIGH8.1An issue in Aver PTC310UV2 v.0.1.0000.59 allows a remote attacker to obtain sensitive information via a crafted request
CVE-2025-45619MEDIUM6.5An issue in Aver PTC310UV2 firmware v.0.1.0000.59 allows a remote attacker to execute arbitrary code via the SendAction ...
CVE-2025-36611HIGH7.8Dell Encryption and Dell Security Management Server, versions prior to 11.11.0, contain an Improper Link Resolution Befo...
CVE-2025-25692MEDIUM6.5A PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitr...
CVE-2025-25691MEDIUM6.5A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute ar...
CVE-2025-8353MEDIUM5.9UI synchronization issue in the Just-in-Time (JIT) access request approval interface in Devolutions Server 2025.2.4.0 an...
CVE-2025-8312HIGH7.1Deadlock in PAM automatic check-in feature in Devolutions Server allows a password to remain valid beyond the end of its...
CVE-2025-54656MEDIUM6.5** UNSUPPORTED WHEN ASSIGNED ** Improper Output Neutralization for Logs vulnerability in Apache Struts. This issue affe...
CVE-2025-50578CRITICAL9.8LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically ...
CVE-2025-54573MEDIUM6.5CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.1.0 through 2.41.0...
CVE-2025-54433HIGH7.2Bugsink is a self-hosted error tracking service. In versions 1.4.2 and below, 1.5.0 through 1.5.4, 1.6.0 through 1.6.3, ...
CVE-2025-53944HIGH7.7AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents. In v0.6...
CVE-2025-53357MEDIUM5.4GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that...
CVE-2025-53113LOW2.7GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that...
CVE-2025-53112MEDIUM4.3GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and...
CVE-2025-53111MEDIUM6.5GLPI is a Free Asset and IT Management Software package. In versions 0.80 through 10.0.18, a lack of permission checks c...
CVE-2025-46811CRITICAL9.8A Missing Authorization vulnerability in SUSE Linux Manager allows anyone with the ability to connect to port 443 of SUS...
CVE-2025-43018MEDIUM5.3Certain HP LaserJet Pro printers may be vulnerable to information disclosure when a non-authenticated user queries a dev...
CVE-2025-54572MEDIUM6.9The Ruby SAML library is for implementing the client side of a SAML authorization. In versions 1.18.0 and below, a denia...
CVE-2025-54430CRITICAL9.1dedupe is a python library that uses machine learning to perform fuzzy matching, deduplication and entity resolution qui...
CVE-2025-54425MEDIUM5.3Umbraco is an ASP.NET CMS. In versions 13.0.0 through 13.9.2, 15.0.0 through 15.4.1 and 16.0.0 through 16.1.0, the conte...
CVE-2025-54410MEDIUM5.2Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Conta...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now