2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-54537MEDIUM5.5In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots
CVE-2025-54536HIGH8.8In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint
CVE-2025-54535HIGH7.5In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms
CVE-2025-54534MEDIUM4.8In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page
CVE-2025-54533MEDIUM4.3In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration
CVE-2025-54532MEDIUM4.3In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependenc...
CVE-2025-54531CRITICAL9.4In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows
CVE-2025-54530CRITICAL9.8In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions
CVE-2025-54529HIGH7.5In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration
CVE-2025-54528HIGH8.8In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow
CVE-2025-54527MEDIUM6.1In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in ...
CVE-2025-50494HIGH7.5Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v...
CVE-2025-50493HIGH7.5Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Doctor Appointment Management S...
CVE-2025-50490HIGH7.5Improper session invalidation in the component /elms/emp-changepassword.php of PHPGurukul Student Result Management Syst...
CVE-2025-6250MEDIUM6.7Prior to 25.4.270.0, when wmic.exe is elevated with a full admin token the user can stop the Defendpoint service, bypass...
CVE-2025-2297HIGH7.8Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challe...
CVE-2025-54418CRITICAL9.8CodeIgniter is a PHP full-stack web framework. A command injection vulnerability present in versions prior to 4.6.2 affe...
CVE-2025-53696CRITICAL9.3iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the ...
CVE-2025-30125CRITICAL9.8An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. All dashcams were shipped with the same default crede...
CVE-2025-8279CRITICAL9.8Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query...
CVE-2025-53695CRITICAL9.4OS Command Injection in iSTAR Ultra products web application allows an authenticated attacker to gain even more privileg...
CVE-2025-32731MEDIUM6.1A reflected cross-site scripting (xss) vulnerability exists in the radiationDoseReport.php functionality of meddream Med...
CVE-2025-30133CRITICAL9.8An issue was discovered on IROAD Dashcam FX2 devices. Bypass of Device Pairing/Registration can occur. It requires devic...
CVE-2025-30126MEDIUM5.3An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Via port 7777 without any need to pair or press a phy...
CVE-2025-30124CRITICAL9.8An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. When a new SD card is inserted into the dashcam, the ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now