2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-54452CRITICAL9.8Improper Authentication vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue ...
CVE-2025-54451CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Samsung Electronics MagicINFO 9 Server allows...
CVE-2025-54450CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi...
CVE-2025-54449CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje...
CVE-2025-54448CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje...
CVE-2025-54447CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje...
CVE-2025-54446CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi...
CVE-2025-54445CRITICAL9.8Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Ser...
CVE-2025-54444CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje...
CVE-2025-54443CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi...
CVE-2025-54442CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje...
CVE-2025-54441HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje...
CVE-2025-54440CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje...
CVE-2025-54439HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje...
CVE-2025-54438CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi...
CVE-2025-8022Rejected reason: Bun Shell does not invoke /bin/sh, or any other interpreter, for template literals created with the $ f...
CVE-2025-8021HIGH7.7All versions of the package files-bucket-server are vulnerable to Directory Traversal where an attacker can traverse the...
CVE-2025-8020HIGH8.2All versions of the package private-ip are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provid...
CVE-2025-43881MEDIUM5.3Improper validation of specified quantity in input issue exists in Real-time Bus Tracking System versions prior to 1.1. ...
CVE-2025-42947MEDIUM5.5SAP FICA ODN framework allows a high privileged user to inject value inside the local variable which can then be execute...
CVE-2025-7722HIGH8.8The Social Streams plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0....
CVE-2025-6261MEDIUM6.4The Fleetwire Fleet Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fleetw...
CVE-2025-6215MEDIUM5.3The Omnishop plugin for WordPress is vulnerable to Unauthenticated Registration Bypass in all versions up to, and includ...
CVE-2025-6214MEDIUM6.5The Omnishop plugin for WordPress is vulnerable to Cross-Site Request Forgery on its /users/delete REST route in all ver...
CVE-2025-6190HIGH8.8The Realty Portal – Agent plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now