2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-51869HIGH7.5Insecure Direct Object Reference (IDOR) vulnerability in Liner thru 2025-06-03 allows attackers to gain sensitive inform...
CVE-2025-51868HIGH7.5Insecure Direct Object Reference (IDOR) vulnerability in Dippy (chat.dippy.ai) v2 allows attackers to gain sensitive inf...
CVE-2025-7935HIGH8.8A vulnerability, which was classified as critical, was found in fuyang_lipengjun platform up to ca9aceff6902feb7b0b6bf51...
CVE-2025-7934HIGH8.8A vulnerability, which was classified as critical, has been found in fuyang_lipengjun platform up to ca9aceff6902feb7b0b...
CVE-2025-51403MEDIUM6.5A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4....
CVE-2025-51401MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the chat transfer function of Live Helper Chat v4.60 allows attacke...
CVE-2025-51400MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Personal Canned Messages of Live Helper Chat v4.60 allows attac...
CVE-2025-51398MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Facebook registration page of Live Helper Chat v4.60 allows att...
CVE-2025-51397MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers...
CVE-2025-51396MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Live Helper Chat v4.60 allows attackers to execute arbitrary web sc...
CVE-2025-36106HIGH8.2IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to view and modify information comin...
CVE-2025-36062HIGH7.5IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could be vulnerable to information exposure due to the use of u...
CVE-2025-36057MEDIUM4.6IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 is vulnerable to authentication bypass by using the Local Authe...
CVE-2025-7962HIGH7.5In Jakarta Mail versions prior to 2.0.2 it is possible to perform an SMTP Injection by utilizing the \r and \n UTF-8 cha...
CVE-2025-7933CRITICAL9.8A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. This vulnerability affects...
CVE-2025-52575MEDIUM6.5EspoCRM is an Open Source CRM (Customer Relationship Management) software. EspoCRM versions 9.1.6 and earlier are vulner...
CVE-2025-44654CRITICAL9.8In Linksys E2500 3.0.04.002, the chroot_local_user option is enabled in the vsftpd configuration file. This could lead t...
CVE-2025-44652HIGH7.5In Netgear RAX30 V1.0.10.94_3, the USERLIMIT_GLOBAL option is set to 0 in multiple bftpd-related configuration files. Th...
CVE-2025-36846CRITICAL9.8An issue was discovered in Eveo URVE Web Manager 27.02.2025. The application exposes a /_internal/pc/vpro.php localhost ...
CVE-2025-36845HIGH8.6An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php allows for Server-Side...
CVE-2025-36107HIGH7.5IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to obtain sensitive information due ...
CVE-2025-7932HIGH8.8A vulnerability classified as critical has been found in D-Link DIR‑817L up to 1.04B01. This affects the function lxmldb...
CVE-2025-7931HIGH7.3A vulnerability was found in code-projects Church Donation System 1.0. It has been rated as critical. Affected by this i...
CVE-2025-7717HIGH7.5Missing Authorization vulnerability in Drupal File Download allows Forceful Browsing.This issue affects File Download: f...
CVE-2025-7716MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Real-time S...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now