2025 CVE Vulnerabilities

45,262 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-53373HIGH8.9Natours is a Tour Booking API. The attacker can easily take over any victim account by injecting an attacker-controlled ...
CVE-2025-52492HIGH7.5A vulnerability has been discovered in the firmware of Paxton Paxton10 before 4.6 SR6. The firmware file, rootfs.tar.gz,...
CVE-2025-48367HIGH7.5Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP p...
CVE-2025-47202CRITICAL9.1In RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 13...
CVE-2025-45479CRITICAL9.8Insufficient security mechanisms for created containers in educoder challenges v1.0 allow attackers to execute arbitrary...
CVE-2025-45065CRITICAL9.8employee record management system in php and mysql v1 was discovered to contain a SQL injection vulnerability via the lo...
CVE-2025-43933CRITICAL9.8fblog through 983bede allows account takeover via the password reset feature because SERVER_NAME is not configured and t...
CVE-2025-43932CRITICAL9.8JobCenter through 7e7b0b2 allows account takeover via the password reset feature because SERVER_NAME is not configured a...
CVE-2025-43931CRITICAL9.8flask-boilerplate through a170e7c allows account takeover via the password reset feature because SERVER_NAME is not conf...
CVE-2025-32023HIGH7.8Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, ...
CVE-2025-26780HIGH7.5An issue was discovered in L2 in Samsung Mobile Processor and Modem Exynos 2400 and Modem 5400. The lack of a length che...
CVE-2025-7133MEDIUM5.4A vulnerability classified as problematic has been found in CodeAstro Online Movie Ticket Booking System 1.0. This affec...
CVE-2025-7132CRITICAL9.8A vulnerability was found in Campcodes Payroll Management System 1.0. It has been rated as critical. Affected by this is...
CVE-2025-6811CRITICAL9.8Mescius ActiveReports.NET TypeResolutionService Deserialization of Untrusted Data Remote Code Execution Vulnerability. T...
CVE-2025-6810CRITICAL9.8Mescius ActiveReports.NET ReadValue Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerab...
CVE-2025-6807HIGH7.5Marvell QConvergeConsole getDriverTmpPath Directory Traversal Information Disclosure Vulnerability. This vulnerability a...
CVE-2025-6806HIGH7.5Marvell QConvergeConsole decryptFile Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows r...
CVE-2025-6805CRITICAL9.1Marvell QConvergeConsole deleteEventLogFile Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerabilit...
CVE-2025-6804HIGH7.5Marvell QConvergeConsole compressFirmwareDumpFiles Directory Traversal Information Disclosure Vulnerability. This vulner...
CVE-2025-6803HIGH7.5Marvell QConvergeConsole compressDriverFiles Directory Traversal Information Disclosure Vulnerability. This vulnerabilit...
CVE-2025-6802CRITICAL9.8Marvell QConvergeConsole getFileFromURL Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability...
CVE-2025-6801HIGH7.5Marvell QConvergeConsole saveNICParamsToFile Directory Traversal Arbitrary File Write Vulnerability. This vulnerability ...
CVE-2025-6800HIGH7.5Marvell QConvergeConsole restoreESwitchConfig Directory Traversal Information Disclosure Vulnerability. This vulnerabili...
CVE-2025-6799HIGH7.5Marvell QConvergeConsole getFileUploadBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability...
CVE-2025-6798CRITICAL9.1Marvell QConvergeConsole deleteAppFile Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability all...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now