2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-49656HIGH7.5Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affe...
CVE-2025-41681MEDIUM4.8A high privileged remote attacker can gain persistent XSS via POST requests due to improper neutralization of special el...
CVE-2025-41679HIGH7.5An unauthenticated remote attacker could exploit a buffer overflow vulnerability in the device causing a denial of servi...
CVE-2025-41678HIGH7.2A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization ...
CVE-2025-41677MEDIUM4.9A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to...
CVE-2025-41676MEDIUM4.9A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to...
CVE-2025-41675HIGH7.2A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communicati...
CVE-2025-41674HIGH7.2A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due t...
CVE-2025-41673HIGH7.2A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms action due to ...
CVE-2025-1469HIGH7.5Authorization Bypass Through User-Controlled Key vulnerability in Turtek Software Eyotek allows Exploitation of Trusted ...
CVE-2025-7369MEDIUM6.1The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v...
CVE-2025-7354MEDIUM6.4The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2025-4685MEDIUM6.4The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2025-4570MEDIUM6.9An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token t...
CVE-2025-4569HIGH7.7An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token t...
CVE-2025-4049HIGH8.6Use of hard-coded, the same among all vulnerable installations SQLite credentials vulnerability in SIGNUM-NET FARA allow...
CVE-2025-7921CRITICAL9.8Certain modem models developed by Askey has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote...
CVE-2025-7920MEDIUM6.1WinMatrix3 Web package developed by Simopro Technology has a Reflected Cross-site Scripting vulnerability, allowing unau...
CVE-2025-7919HIGH7.1WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability, allowing unauthenticated remot...
CVE-2025-7344HIGH8.8The EAI developed by Digiwin has a Privilege Escalation vulnerability, allowing remote attackers with regular privileges...
CVE-2025-7343CRITICAL9.8The SFT developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbi...
CVE-2025-24938HIGH8.4The web application allows user input to pass unfiltered to a command executed on the underlying operating system. An at...
CVE-2025-24937CRITICAL9File contents could be read from the local file system by an attacker. Additionally, malicious code could be inserted in...
CVE-2025-24936CRITICAL9The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The v...
CVE-2025-0664MEDIUM6.7A locally authenticated, privileged user can craft a malicious OpenSSL configuration file, potentially leading the agent...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now