2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-7918CRITICAL9.8WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability, allowing unauthenticated remot...
CVE-2025-7917HIGH8.6WinMatrix3 Web package developed by Simopro Technology has an Arbitrary File Upload vulnerability, allowing remote attac...
CVE-2025-7916CRITICAL9.8WinMatrix3 developed by Simopro Technology has an Insecure Deserialization vulnerability, allowing unauthenticated remot...
CVE-2025-54352LOW3.7WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC...
CVE-2025-7915CRITICAL9.8A vulnerability was found in Chanjet CRM 1.0 and classified as critical. Affected by this issue is some unknown function...
CVE-2025-7914HIGH8.8A vulnerability has been found in Tenda AC6 15.03.06.50 and classified as critical. Affected by this vulnerability is th...
CVE-2025-7913HIGH8.8A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. Affected is the funct...
CVE-2025-7912HIGH8.8A vulnerability, which was classified as critical, has been found in TOTOLINK T6 4.1.5cu.748_B20211015. This issue affec...
CVE-2025-7911CRITICAL9.8A vulnerability classified as critical was found in D-Link DI-8100 1.0. This vulnerability affects the function sprintf ...
CVE-2025-53771MEDIUM6.5Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a networ...
CVE-2025-7910HIGH8.8A vulnerability classified as critical has been found in D-Link DIR-513 1.10. This affects the function sprintf of the f...
CVE-2025-7909HIGH8.8A vulnerability was found in D-Link DIR-513 1.0. It has been rated as critical. Affected by this issue is the function s...
CVE-2025-7908HIGH8.8A vulnerability was found in D-Link DI-8100 1.0. It has been declared as critical. Affected by this vulnerability is the...
CVE-2025-7907MEDIUM4.3A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. It has been classified as problematic. Affected is an unkn...
CVE-2025-54319MEDIUM6.3An issue was discovered in Westermo WeOS 5 (5.24 through 5.24.4). A threat actor potentially can gain unauthorized acces...
CVE-2025-7906MEDIUM5.4A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1 and classified as critical. This issue affects the function...
CVE-2025-7905HIGH8.8A vulnerability has been found in itsourcecode Insurance Management System 1.0 and classified as critical. This vulnerab...
CVE-2025-54317HIGH8.4An issue was discovered in Logpoint before 7.6.0. An attacker with operator privileges can exploit a path traversal vuln...
CVE-2025-54316MEDIUM4.9An issue was discovered in Logpoint before 7.6.0. When creating reports, attackers can create custom Jinja templates tha...
CVE-2025-49087LOW3.7In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding removal allows an attacker to...
CVE-2025-47917CRITICAL9.8Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance wit...
CVE-2025-48965HIGH7.5Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_named_data can trigger conflicting data ...
CVE-2025-7904HIGH8.8A vulnerability, which was classified as critical, was found in itsourcecode Insurance Management System 1.0. This affec...
CVE-2025-7903MEDIUM5.4A vulnerability classified as problematic was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability i...
CVE-2025-7902MEDIUM5.4A vulnerability classified as problematic has been found in yangzongzhuan RuoYi up to 4.8.1. Affected is the function ad...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now