2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-54767MEDIUM6.5An authenticated, read-only user can kill any processes running on the Xormon Original virtual appliance as the lpar2rrd...
CVE-2025-54766MEDIUM5.3An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level ...
CVE-2025-54765MEDIUM5.3An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level ...
CVE-2025-54429MEDIUM6.9Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. There are various account addre...
CVE-2025-54428CRITICAL9.8RevelaCode is an AI-powered faith-tech project that decodes biblical verses, prophecies and global events into accessibl...
CVE-2025-54427MEDIUM6.9Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. The extrinsic note_min_gas_pric...
CVE-2025-54426CRITICAL9.9Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. In versions prior to commit 36f...
CVE-2025-54423MEDIUM6.1copyparty is a portable file server. In versions up to and including versions 1.18.4, an unauthenticated attacker is abl...
CVE-2025-54419CRITICAL10A SAML library not dependent on any frameworks that runs in Node. In version 5.0.1, Node-SAML loads the assertion from t...
CVE-2025-50486HIGH7.1Improper session invalidation in the component /carrental/update-password.php of PHPGurukul Car Rental Project v3.0 allo...
CVE-2025-50485HIGH7.1Improper session invalidation in the component /crm/change-password.php of PHPGurukul Online Course Registration v3.1 al...
CVE-2025-29534HIGH8.8An authenticated remote code execution vulnerability in PowerStick Wave Dual-Band Wifi Extender V1.0 allows an attacker ...
CVE-2025-8283LOW3.7A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman se...
CVE-2025-8194HIGH7.5There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar...
CVE-2025-50487HIGH7.1Improper session invalidation in the component /bbdms/change-password.php of PHPGurukul Blood Bank & Donor Management Sy...
CVE-2025-50484HIGH7.1Improper session invalidation in the component /crm/change-password.php of PHPGurukul Small CRM v3.0 allows attackers to...
CVE-2025-54299CRITICAL9.4A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered.
CVE-2025-54298CRITICAL9.4A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was discovered.
CVE-2025-50492HIGH7.5Improper session invalidation in the component /edms/change-password.php of PHPGurukul e-Diary Management System v1 allo...
CVE-2025-50491HIGH7.1Improper session invalidation in the component /banker/change-password.php of PHPGurukul Bank Locker Management System v...
CVE-2025-50489HIGH7.5Improper session invalidation in the component /srms/change-password.php of PHPGurukul Student Result Management System ...
CVE-2025-50488HIGH7.1Improper session invalidation in the component /library/change-password.php of PHPGurukul Online Library Management Syst...
CVE-2025-43023CRITICAL9.1A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software documentation. This...
CVE-2025-7676MEDIUM5.4DLL hijacking of all PE32 executables when run on Windows for ARM64 CPU architecture. This allows an attacker to execute...
CVE-2025-54538MEDIUM5.5In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now