2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-54060HIGH8.8WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection...
CVE-2025-54058HIGH8.8WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection...
CVE-2025-47189MEDIUM6.1Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error d...
CVE-2025-53946HIGH8.8WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection...
CVE-2025-53941MEDIUM6.1Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Versions prior to ...
CVE-2025-53928CRITICAL9.8MaxKB is an open-source AI assistant for enterprise. Prior to versions 1.10.9-lts and 2.0.0, a Remote Command Execution ...
CVE-2025-53927MEDIUM6.3MaxKB is an open-source AI assistant for enterprise. Prior to version 2.0.0, the sandbox design rules can be bypassed be...
CVE-2025-53909HIGH7.2mailcow: dockerized is an open source groupware/email suite based on docker. A Server-Side Template Injection (SSTI) vul...
CVE-2025-51630CRITICAL9.8TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a buffer overflow via the ePort parameter in the functi...
CVE-2025-40924MEDIUM6.5Catalyst::Plugin::Session before version 0.44 for Perl generates session ids insecurely. The session id is generated fr...
CVE-2025-1713HIGH7.5When setting up interrupt remapping for legacy PCI(-X) devices, including PCI(-X) bridges, a lookup of the upstream brid...
CVE-2025-5346MEDIUM5.1Bluebird devices contain a pre-loaded barcode scanner application. This application exposes an unsecured broadcast recei...
CVE-2025-5345MEDIUM6.3Bluebird devices contain a pre-loaded file manager application. This application exposes an unsecured service provider "...
CVE-2025-5344HIGH8.5Bluebird devices contain a pre-loaded kiosk application. This application exposes an unsecured service provider "com.blu...
CVE-2025-52933Rejected reason: 3rd party vulnerability
CVE-2025-3415MEDIUM4.3Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not p...
CVE-2025-4302MEDIUM5.3The Stop User Enumeration WordPress plugin before version 1.7.3 blocks REST API /wp-json/wp/v2/users/ requests for non-a...
CVE-2025-7735HIGH8.7The Hospital Information System developed by UNIMAX has a SQL Injection vulnerability, allowing unauthenticated remote a...
CVE-2025-7712CRITICAL9.1The Madara - Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation...
CVE-2025-7729MEDIUM5.4A vulnerability classified as problematic was found in Scada-LTS up to 2.7.8.1. Affected by this vulnerability is an unk...
CVE-2025-7728MEDIUM5.4A vulnerability classified as problematic has been found in Scada-LTS up to 2.7.8.1. Affected is an unknown function of ...
CVE-2025-5396CRITICAL9.8The Bears Backup plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.0...
CVE-2025-34132CRITICAL9.3A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_...
CVE-2025-34130HIGH8.7An unauthenticated arbitrary file read exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2....
CVE-2025-34129HIGH8.7A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now