2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-53840LOW2.4Icinga DB Web provides a graphical interface for Icinga monitoring. Starting in version 1.2.0 and prior to version 1.2.2...
CVE-2025-40919MEDIUM6.5Authen::DigestMD5 versions 0.01 through 0.02 for Perl generate the cnonce insecurely. The cnonce (client nonce) is gene...
CVE-2025-40918MEDIUM6.5Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (clien...
CVE-2025-40913MEDIUM6.5Net::Dropbear versions through 0.16 for Perl contains a dependency that may be susceptible to an integer overflow. Net:...
CVE-2025-40776HIGH8.6A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-pois...
CVE-2025-3871MEDIUM5.3Broken access control in Fortra's GoAnywhere MFT prior to 7.8.1 allows an attacker to create a denial of service situati...
CVE-2025-40923HIGH7.3Plack-Middleware-Session before version 0.35 for Perl generates session ids insecurely. The default session id generato...
CVE-2025-34300CRITICAL10A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the  ci...
CVE-2025-53758MEDIUM5.1This vulnerability exists in Digisol DG-GR6821AC Router due to use of default admin credentials at its web management in...
CVE-2025-53757HIGH8.7This vulnerability exists in Digisol DG-GR6821AC Router due to misconfiguration of both Secure and HttpOnly flags on ses...
CVE-2025-53756HIGH8.7This vulnerability exists in Digisol DG-GR6821AC Router due to cleartext transmission of credentials in its web manageme...
CVE-2025-53755MEDIUM5.1This vulnerability exists in Digisol DG-GR6821AC Router due to storage of credentials and PINS without encryption in the...
CVE-2025-53754MEDIUM5.1This vulnerability exists in Digisol DG-GR6821AC Router due to hard-coded Root Access Credentials in system configuratio...
CVE-2025-52836CRITICAL9.8Incorrect Privilege Assignment vulnerability in Unity Business Technology Pty Ltd The E-Commerce ERP profitori allows Pr...
CVE-2025-52819HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pakkemx Pakke Enví...
CVE-2025-52804HIGH7.5Missing Authorization vulnerability in uxper Nuss nuss allows Accessing Functionality Not Properly Constrained by ACLs.T...
CVE-2025-52803HIGH7.5Missing Authorization vulnerability in uxper Sala allows Accessing Functionality Not Properly Constrained by ACLs. This ...
CVE-2025-52787HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EZiHosting Tennis ...
CVE-2025-52786HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kingdom Creation M...
CVE-2025-52779HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in karimmughal Dot ht...
CVE-2025-52777HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cmsMinds Pay with ...
CVE-2025-52714CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Travele...
CVE-2025-50028MEDIUM6.5Missing Authorization vulnerability in CodeSolz Ultimate Push Notifications ultimate-push-notifications allows Exploitin...
CVE-2025-49888HIGH7.1Missing Authorization vulnerability in pimwick PW WooCommerce On Sale! pw-woocommerce-on-sale allows Exploiting Incorrec...
CVE-2025-49884MEDIUM6.5Missing Authorization vulnerability in alexvtn Internal Linking of Related Contents internal-linking-of-related-contents...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now