2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-0886HIGH8.5An incorrect permissions vulnerability was reported in Elliptic Labs Virtual Lock Sensor that could allow a local, authe...
CVE-2025-7750CRITICAL9.8A vulnerability, which was classified as critical, was found in code-projects Online Appointment Booking System 1.0. Aff...
CVE-2025-7472HIGH7.5A local privilege escalation vulnerability in the Intercept X for Windows installer prior version 1.22 can lead to a loc...
CVE-2025-54070MEDIUM6.9OpenZeppelin Contracts is a library for secure smart contract development. Starting in version 5.2.0 and prior to versio...
CVE-2025-54068CRITICAL9.8Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauth...
CVE-2025-53817HIGH7.57-Zip is a file archiver with a high compression ratio. 7-Zip supports extracting from Compound Documents. Prior to vers...
CVE-2025-53816HIGH7.57-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to m...
CVE-2025-50240CRITICAL9.8nbcio-boot v1.0.3 was discovered to contain a SQL injection vulnerability via the userIds parameter at /sys/user/deleteR...
CVE-2025-46102MEDIUM5.4Cross Site Scripting vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Referenc...
CVE-2025-7749CRITICAL9.8A vulnerability, which was classified as critical, has been found in code-projects Online Appointment Booking System 1.0...
CVE-2025-7748LOW3.5A vulnerability classified as problematic was found in ZCMS 3.6.0. This vulnerability affects unknown code of the compon...
CVE-2025-7747HIGH8.8A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. This affects the function fromWizardHandle...
CVE-2025-53644CRITICAL9.8OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 have an uninitialized pointer variable on s...
CVE-2025-53638MEDIUM6.9Solady is software that provides Solidity snippets with APIs. Starting in version 0.0.125 and prior to version 0.1.24, w...
CVE-2025-51497MEDIUM5.5An issue was discovered in AdGuard plugin before 1.11.22 for Safari on MacOS. AdGaurd verbosely logged each url that Saf...
CVE-2025-23263HIGH7.6NVIDIA DOCA-Host and Mellanox OFED contain a vulnerability in the VGT+ feature, where an attacker on a VM might cause es...
CVE-2025-7339LOW3.4on-headers is a node.js middleware for listening to when a response writes headers. A bug in on-headers versions `<1.1.0...
CVE-2025-7338HIGH7.5Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1...
CVE-2025-53867CRITICAL9.8Island Lake WebBatch before 2025C allows Remote Code Execution via a crafted URL.
CVE-2025-52046CRITICAL9.8Totolink A3300R V17.0.0cu.596_B20250515 was found to contain a command injection vulnerability in the sub_4197C0 functio...
CVE-2025-25257CRITICAL9.8An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi...
CVE-2025-54066MEDIUM4.7DiracX-Web is a web application that provides an interface to interact with the DiracX services. Prior to version 0.1.0-...
CVE-2025-54064MEDIUM6.9Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific da...
CVE-2025-54062HIGH8.8WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection...
CVE-2025-54061HIGH8.8WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now