2025 CVE Vulnerabilities

45,264 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-34063CRITICAL10A cryptographic authentication bypass vulnerability exists in OneLogin AD Connector prior to 6.1.5 due to the exposure o...
CVE-2025-34062MEDIUM5.7An information disclosure vulnerability exists in OneLogin AD Connector versions prior to 6.1.5 via the /api/adc/v4/conf...
CVE-2025-34060CRITICAL10A PHP objection injection vulnerability exists in the Monero Project’s Laravel-based forum software due to unsafe handli...
CVE-2025-34059HIGH8.7An SQL injection vulnerability exists in the Dahua Smart Cloud Gateway Registration Management Platform via the username...
CVE-2025-34058HIGH8.7Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate ...
CVE-2025-34056CRITICAL9.4An OS command injection vulnerability exists in AVTECH IP camera, DVR, and NVR devices via the PwdGrp.cgi endpoint, whic...
CVE-2025-34055CRITICAL9.4An OS command injection vulnerability exists in AVTECH DVR, NVR, and IP camera devices within the adcommand.cgi endpoint...
CVE-2025-34054CRITICAL10An unauthenticated command injection vulnerability exists in AVTECH DVR devices via Search.cgi?action=cgi_query. The use...
CVE-2025-34053MEDIUM6.9An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr(...
CVE-2025-34052Rejected reason: An unauthenticated endpoint that exposes firmware version, MAC address, and supported codecs is not ind...
CVE-2025-34051MEDIUM6.9A server-side request forgery vulnerability exists in multiple firmware versions of AVTECH DVR devices that exposes the ...
CVE-2025-34050MEDIUM5.1A cross-site request forgery (CSRF) vulnerability exists in the web interface of AVTECH IP camera, DVR, and NVR devices....
CVE-2025-6956CRITICAL9.8A vulnerability was found in Campcodes Employee Management System 1.0. It has been classified as critical. This affects ...
CVE-2025-6955CRITICAL9.8A vulnerability was found in Campcodes Employee Management System 1.0 and classified as critical. Affected by this issue...
CVE-2025-6954CRITICAL9.8A vulnerability has been found in Campcodes Employee Management System 1.0 and classified as critical. Affected by this ...
CVE-2025-6953HIGH8.8A vulnerability, which was classified as critical, was found in TOTOLINK A3002RU 3.0.0-B20230809.1615. Affected is an un...
CVE-2025-6920MEDIUM5.3A flaw was found in the authentication enforcement mechanism of a model inference API in ai-inference-server. All /v1/* ...
CVE-2025-49029CRITICAL9.1Improper Control of Generation of Code ('Code Injection') vulnerability in bitto.kazi Custom Login And Signup Widget cus...
CVE-2025-45872CRITICAL9.8zrlog v3.1.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the downloadUrl parameter.
CVE-2025-37097HIGH7.5A vulnerability in HPE Insight Remote Support (IRS) prior to v7.15.0.646 may allow an unauthenticated denial of service
CVE-2025-36582HIGH7.5Dell NetWorker, versions 19.12.0.1 and prior, contains a Selection of Less-Secure Algorithm During Negotiation ('Algorit...
CVE-2025-6952MEDIUM4.8A vulnerability, which was classified as problematic, has been found in Open5GS up to 2.7.5. This issue affects the func...
CVE-2025-6951MEDIUM4.3A vulnerability classified as problematic was found in SAFECAM X300 up to 20250611. This vulnerability affects unknown c...
CVE-2025-5314MEDIUM6.1The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to DOM-Based Ref...
CVE-2025-49483MEDIUM5.4Improper Resource Shutdown or Release vulnerability in ASR180x 、ASR190x in tr069 modules allows Resource Leak Exposure....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now