2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-33077HIGH8.8IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 is vulnerable to a stack-based buffer overflow, caused b...
CVE-2025-33076HIGH8.8IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 is vulnerable to a stack-based buffer overflow, caused b...
CVE-2025-33020HIGH7.5IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 transmits sensitive information without encryption that ...
CVE-2025-54090MEDIUM6.3A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recomm...
CVE-2025-46099HIGH7.2In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module direc...
CVE-2025-40599CRITICAL9.1An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote att...
CVE-2025-4411MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dataprom In...
CVE-2025-54297HIGH7A stored XSS vulnerability in CComment component 5.0.0-6.1.14 for Joomla was discovered.
CVE-2025-54296HIGH7A stored XSS vulnerability in ProFiles component 1.0-1.5.0 for Joomla was discovered.
CVE-2025-54295MEDIUM5.1A Reflected XSS vulnerability in DJ-Reviews component 1.0-1.3.6 for Joomla was discovered.
CVE-2025-54294CRITICAL9.3A SQLi vulnerability in Komento component 4.0.0-4.0.7for Joomla was discovered. The issue allows unprivileged users to e...
CVE-2025-50127HIGH8.5A SQLi vulnerability in DJ-Flyer component 1.0-3.2 for Joomla was discovered. The issue allows privileged users to execu...
CVE-2025-4296MEDIUM4.7URL Redirection to Untrusted Site ('Open Redirect') vulnerability in HotelRunner B2B allows Forceful Browsing. This iss...
CVE-2025-27930MEDIUM5.4Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in th...
CVE-2025-53882MEDIUM4.8A Reliance on Untrusted Inputs in a Security Decision vulnerability in the logrotate configuration for openSUSE mailman3...
CVE-2025-41687CRITICAL9.8An unauthenticated remote attacker may use a stack based buffer overflow in the u-link Management API to gain full acces...
CVE-2025-41684HIGH8.8An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of ...
CVE-2025-41683HIGH8.8An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of ...
CVE-2025-8070CRITICAL9.2The Windows service configuration of ABP and AES contains an unquoted ImagePath registry value vulnerability. This allow...
CVE-2025-31701HIGH8.1A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending sp...
CVE-2025-31700HIGH8.1A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending sp...
CVE-2025-6174MEDIUM6.1The Qwizcards | online quizzes and flashcards WordPress plugin through 3.9.4 does not sanitise and escape the "_styleshe...
CVE-2025-54455CRITICAL9.8Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This ...
CVE-2025-54454CRITICAL9.8Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This ...
CVE-2025-54453CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now