2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-69770CRITICAL10A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execu...
CVE-2025-66676MEDIUM6.2An issue in IObit Unlocker v1.3.0.11 allows attackers to cause a Denial of Service (DoS) via a crafted request.
CVE-2025-70123HIGH7.5An improper input validation and protocol compliance vulnerability in free5GC v4.0.1 allows remote attackers to cause a ...
CVE-2025-70122HIGH7.5A heap buffer overflow vulnerability in the UPF component of free5GC v4.0.1 allows remote attackers to cause a denial of...
CVE-2025-70121HIGH7.5An array index out of bounds vulnerability in the AMF component of free5GC v4.0.1 allows remote attackers to cause a den...
CVE-2025-1790MEDIUM5.8Local privilege escalation in Genetec Sipelia Plugin. An authenticated low-privileged Windows user could exploit this vu...
CVE-2025-70095MEDIUM6.5A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 all...
CVE-2025-70094MEDIUM6.5A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attacker...
CVE-2025-70093HIGH7.4An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response.
CVE-2025-70091MEDIUM6.5A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute...
CVE-2025-14349HIGH8.8Privilege Defined With Unsafe Actions, Missing Authentication for Critical Function vulnerability in Universal Software ...
CVE-2025-33042HIGH7.3Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific...
CVE-2025-48023MEDIUM6.5A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ...
CVE-2025-48022MEDIUM6.5A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ...
CVE-2025-48021MEDIUM6.5A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ...
CVE-2025-15520MEDIUM4.3The RegistrationMagic WordPress plugin before 6.0.7.2 checks nonces but not capabilities, allowing for the disclosure o...
CVE-2025-48020MEDIUM6.5A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ...
CVE-2025-48019MEDIUM6.5A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ...
CVE-2025-1924HIGH8.2A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ...
CVE-2025-9293HIGH8.1A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated s...
CVE-2025-9292HIGH7.5A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed u...
CVE-2025-40905HIGH7.3WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptograp...
CVE-2025-70092MEDIUM5.5A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute...
CVE-2025-70845MEDIUM6.1lty628 aidigu v1.9.1 is vulnerable to Cross Site Scripting (XSS) exists in the /setting/ page where the "intro" field is...
CVE-2025-14282MEDIUM5.4A flaw was found in Dropbear. When running in multi-user mode and authenticating users, the dropbear ssh server does the...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now