2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-51864MEDIUM6.5A reflected cross-site scripting (XSS) vulnerability exists in AIBOX LLM chat (chat.aibox365.cn) through 2025-05-27, all...
CVE-2025-51863MEDIUM6.1Self Cross Site Scripting (XSS) vulnerability in ChatGPT Unli (ChatGPTUnli.com) thru 2025-05-26 allows attackers to exec...
CVE-2025-51862MEDIUM6.1Insecure Direct Object Reference (IDOR) vulnerability in TelegAI (telegai.com) thru 2025-05-26 in its chat component. An...
CVE-2025-51860MEDIUM6.1Stored Cross-Site Scripting (XSS) in TelegAI (telegai.com) 2025-05-26 in its chat component and character container comp...
CVE-2025-51859MEDIUM6.5Stored Cross-Site Scripting (XSS) vulnerability in Chaindesk thru 2025-05-26 in its agent chat component. An attacker ca...
CVE-2025-51858MEDIUM6.1Self Cross-Site Scripting (XSS) vulnerability in ChatPlayground.ai through 2025-05-24, allows attackers to execute arbit...
CVE-2025-4878LOW3.6A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_f...
CVE-2025-8017HIGH8.8A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. Affected is the function formSet...
CVE-2025-51867MEDIUM6.5Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI (deepfiction.ai) thru June 3, 2025, allowing att...
CVE-2025-4295MEDIUM4.6Improper Validation of Certificate with Host Mismatch vulnerability in HotelRunner B2B allows HTTP Response Splitting. ...
CVE-2025-4294MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HotelRunner...
CVE-2025-34143CRITICAL9.3An authentication bypass vulnerability exists in ETQ Reliance on the CG (legacy) platform. The application allowed login...
CVE-2025-34142MEDIUM6.9An XML External Entity (XXE) injection vulnerability exists in ETQ Reliance on the CG (legacy) platform within the `/res...
CVE-2025-34141MEDIUM5.1A reflected cross-site scripting (XSS) vulnerability exists in ETQ Reliance CG (legacy) platform within the `SQLConverte...
CVE-2025-34140HIGH8.7An authorization bypass vulnerability exists in ETQ Reliance (legacy CG and NXG SaaS platforms). By appending a specific...
CVE-2025-7705HIGH8.6: Active Debug Code vulnerability in ABB Switch Actuator 4 DU-83330, ABB Switch actuator, door/light 4 DU -83330-500.Thi...
CVE-2025-4285CRITICAL10Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rolantis Informati...
CVE-2025-4284MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Rolantis In...
CVE-2025-7900MEDIUM6.5The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of user...
CVE-2025-7899MEDIUM6The powermail extension for TYPO3 allows Insecure Direct Object Reference resulting in download of arbitrary files from ...
CVE-2025-7692HIGH8.1The Orion Login with SMS plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includin...
CVE-2025-7687MEDIUM6.1The Latest Post Accordian Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...
CVE-2025-7685MEDIUM6.1The Like & Share My Site plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2025-7427MEDIUM5.9Uncontrolled Search Path Element in Arm Development Studio before 2025 may allow an attacker to perform a DLL hijacking ...
CVE-2025-6213HIGH7.2The Nginx Cache Purge Preload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and inc...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now