2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-7715MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Block Attri...
CVE-2025-7393CRITICAL9.8Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Mail Login allows Brute Force.This iss...
CVE-2025-7392MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Cookies Add...
CVE-2025-54082HIGH8.1marshmallow-packages/nova-tiptap is a rich text editor for Laravel Nova based on tiptap. Prior to 5.7.0, a vulnerability...
CVE-2025-44653HIGH7.5In H3C GR2200 MiniGR1A0V100R016, the USERLIMIT_GLOBAL option is set to 0 in the /etc/bftpd.conf. This can cause DoS atta...
CVE-2025-44649HIGH7.5In the configuration file of racoon in the TRENDnet TEW-WLC100P 2.03b03, the first item of exchage_mode is set to aggres...
CVE-2025-43720MEDIUM6.5Headwind MDM before 5.33.1 makes configuration details accessible to unauthorized users. The Configuration profile is ex...
CVE-2025-36603MEDIUM4.8Dell AppSync, version(s) 4.6.0.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low...
CVE-2025-32744MEDIUM6.6Dell AppSync, version(s) 4.6.0.0, contains an Unrestricted Upload of File with Dangerous Type vulnerability. A high priv...
CVE-2025-30477MEDIUM4.9Dell PowerScale OneFS, versions prior to 9.11.0.0, contains a use of a broken or risky cryptographic algorithm vulnerabi...
CVE-2025-7930CRITICAL9.8A vulnerability was found in code-projects Church Donation System 1.0. It has been declared as critical. Affected by thi...
CVE-2025-7929CRITICAL9.8A vulnerability was found in code-projects Church Donation System 1.0. It has been classified as critical. Affected is a...
CVE-2025-52374MEDIUM4.6Use of hardcoded cryptographic key in Encryption.cs in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passw...
CVE-2025-52373MEDIUM4.6Use of hardcoded cryptographic key in BlowFish.cpp in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwo...
CVE-2025-52372MEDIUM5.1An issue in hMailServer v.5.8.6 allows a local attacker to obtain sensitive information via the hmailserver/installation...
CVE-2025-44658CRITICAL9.8In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to on...
CVE-2025-44657LOW3.9In Linksys EA6350 V2.1.2, the chroot_local_user option is enabled in the dynamically generated vsftpd configuration file...
CVE-2025-44655CRITICAL9.8In TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9, the chroot_local_user option is enabled in the vsftpd.conf. This co...
CVE-2025-44651HIGH7.5In TRENDnet TPL-430AP FW1.0, the USERLIMIT_GLOBAL option is set to 0 in the bftpd-related configuration file. This can c...
CVE-2025-44650HIGH7.5In Netgear R7000 V1.3.1.64_10.1.36 and EAX80 V1.0.1.70_1.0.2, the USERLIMIT_GLOBAL option is set to 0 in the bftpd.conf ...
CVE-2025-44647HIGH7.3In TRENDnet TEW-WLC100P 2.03b03, the i_dont_care_about_security_and_use_aggressive_mode_psk option is enabled in the str...
CVE-2025-7928CRITICAL9.8A vulnerability was found in code-projects Church Donation System 1.0 and classified as critical. This issue affects som...
CVE-2025-7927HIGH8.8A vulnerability has been found in PHPGurukul Online Banquet Booking System 1.0 and classified as critical. This vulnerab...
CVE-2025-46123HIGH7.2An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDir...
CVE-2025-46122CRITICAL9.1An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticat...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now