2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-20007——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2025-69770CRITICAL10A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execu...
CVE-2025-66676MEDIUM6.2An issue in IObit Unlocker v1.3.0.11 allows attackers to cause a Denial of Service (DoS) via a crafted request.
CVE-2025-70123HIGH7.5An improper input validation and protocol compliance vulnerability in free5GC v4.0.1 allows remote attackers to cause a ...
CVE-2025-70122HIGH7.5A heap buffer overflow vulnerability in the UPF component of free5GC v4.0.1 allows remote attackers to cause a denial of...
CVE-2025-70121HIGH7.5An array index out of bounds vulnerability in the AMF component of free5GC v4.0.1 allows remote attackers to cause a den...
CVE-2025-1790MEDIUM5.8Local privilege escalation in Genetec Sipelia Plugin. An authenticated low-privileged Windows user could exploit this vu...
CVE-2025-70095MEDIUM6.5A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 all...
CVE-2025-70094MEDIUM6.5A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attacker...
CVE-2025-70093HIGH7.4An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response.
CVE-2025-70091MEDIUM6.5A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute...
CVE-2025-14349HIGH8.8Privilege Defined With Unsafe Actions, Missing Authentication for Critical Function vulnerability in Universal Software ...
CVE-2025-33042HIGH7.3Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific...
CVE-2025-48023MEDIUM6.5A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ...
CVE-2025-48022MEDIUM6.5A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ...
CVE-2025-48021MEDIUM6.5A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ...
CVE-2025-15520MEDIUM4.3The RegistrationMagic WordPress plugin before 6.0.7.2 checks nonces but not capabilities, allowing for the disclosure o...
CVE-2025-48020MEDIUM6.5A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ...
CVE-2025-48019MEDIUM6.5A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ...
CVE-2025-1924HIGH8.2A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ...
CVE-2025-9293HIGH8.1A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated s...
CVE-2025-9292HIGH7.5A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed u...
CVE-2025-40905HIGH7.3WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptograp...
CVE-2025-70092MEDIUM5.5A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute...
CVE-2025-70845MEDIUM6.1lty628 aidigu v1.9.1 is vulnerable to Cross Site Scripting (XSS) exists in the /setting/ page where the "intro" field is...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now