2025 CVE Vulnerabilities

45,264 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-53103MEDIUM5.8JUnit is a testing framework for Java and the JVM. From version 5.12.0 to 5.13.1, JUnit's support for writing Open Test ...
CVE-2025-53100HIGH8.6RestDB's Codehooks.io MCP Server is an MCP server on the Codehooks.io platform. Prior to version 0.2.2, the MCP server i...
CVE-2025-52294MEDIUM5.7Insufficient validation of the screen lock mechanism in Trust Wallet v8.45 allows physically proximate attackers to bypa...
CVE-2025-45083MEDIUM6.1Incorrect access control in Ullu (Android version v2.9.929 and IOS version v2.8.0) allows attackers to bypass parental p...
CVE-2025-45081HIGH8.8Misconfigured settings in IITB SSO v1.1.0 allow attackers to access sensitive application data.
CVE-2025-45080Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2025-37099CRITICAL9.8A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
CVE-2025-34081HIGH7.5The Contec Co.,Ltd. CONPROSYS HMI System (CHS) exposes a PHP phpinfo() debug page to unauthenticated users that may cont...
CVE-2025-34080MEDIUM6.1The Contec Co.,Ltd. CONPROSYS HMI System (CHS) is vulnerable to Cross-Site Scripting (XSS) in the getqsetting.php functi...
CVE-2025-6297HIGH8.2It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a...
CVE-2025-6963CRITICAL9.8A vulnerability has been found in Campcodes Employee Management System 1.0 and classified as critical. This vulnerabilit...
CVE-2025-6962CRITICAL9.8A vulnerability, which was classified as critical, was found in Campcodes Employee Management System 1.0. This affects a...
CVE-2025-6961CRITICAL9.8A vulnerability, which was classified as critical, has been found in Campcodes Employee Management System 1.0. Affected ...
CVE-2025-50641MEDIUM6.5Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the addWifiMacFilter function via the parameter deviceId...
CVE-2025-6960CRITICAL9.8A vulnerability classified as critical was found in Campcodes Employee Management System 1.0. Affected by this vulnerabi...
CVE-2025-6959CRITICAL9.8A vulnerability classified as critical has been found in Campcodes Employee Management System 1.0. Affected is an unknow...
CVE-2025-6958CRITICAL9.8A vulnerability was found in Campcodes Employee Management System 1.0. It has been rated as critical. This issue affects...
CVE-2025-6957CRITICAL9.8A vulnerability was found in Campcodes Employee Management System 1.0. It has been declared as critical. This vulnerabil...
CVE-2025-53099HIGH7.5Sentry is a developer-first error tracking and performance monitoring tool. Prior to version 25.5.0, an attacker with a ...
CVE-2025-50405MEDIUM6.5Intelbras RX1500 Router v2.2.17 and before is vulnerable to Incorrect Access Control in the FirmwareUpload function and ...
CVE-2025-50404MEDIUM5.3Intelbras RX1500 Router v2.2.17 and before is vulnerable to Integer Overflow. The websReadEvent function incorrectly use...
CVE-2025-37098HIGH7.5A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
CVE-2025-34066HIGH8.3An improper certificate validation vulnerability exists in AVTECH IP cameras, DVRs, and NVRs due to the use of wget with...
CVE-2025-34065MEDIUM6.9An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr(...
CVE-2025-34064CRITICAL9A cloud infrastructure misconfiguration in OneLogin AD Connector results in log data being sent to a hardcoded S3 bucket...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now