2025 CVE Vulnerabilities

45,266 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-36027MEDIUM5.4IBM Datacap 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim. By pe...
CVE-2025-36026MEDIUM4.3IBM Datacap 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or session cookies. Atta...
CVE-2025-53098HIGH8.1Roo Code is an AI-powered autonomous coding agent. The project-specific MCP configuration for the Roo Code agent is stor...
CVE-2025-53097HIGH7.5Roo Code is an AI-powered autonomous coding agent. Prior to version 3.20.3, there was an issue where the Roo Code agent'...
CVE-2025-6778MEDIUM4.8A vulnerability, which was classified as problematic, was found in code-projects Food Distributor Site 1.0. Affected is ...
CVE-2025-6777CRITICAL9.8A vulnerability, which was classified as critical, has been found in code-projects Food Distributor Site 1.0. This issue...
CVE-2025-6776CRITICAL9.8A vulnerability classified as critical was found in xiaoyunjie openvpn-cms-flask up to 1.2.7. This vulnerability affects...
CVE-2025-6775CRITICAL9.8A vulnerability classified as critical has been found in xiaoyunjie openvpn-cms-flask up to 1.2.7. This affects the func...
CVE-2025-6774MEDIUM6.3A vulnerability was found in gooaclok819 sublinkX up to 1.8. It has been rated as critical. Affected by this issue is th...
CVE-2025-53094HIGH8.7ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. In version...
CVE-2025-6773MEDIUM5.3A vulnerability was found in HKUDS LightRAG up to 1.3.8. It has been declared as critical. Affected by this vulnerabilit...
CVE-2025-6772HIGH7.5A vulnerability was found in eosphoros-ai db-gpt up to 0.7.2. It has been classified as critical. Affected is the functi...
CVE-2025-6522MEDIUM5.4Unauthenticated users on an adjacent network with the Sight Bulb Pro can run shell commands as root through a vulnerabl...
CVE-2025-5310CRITICAL9.8Dover Fueling Solutions ProGauge MagLink LX Consoles expose an undocumented and unauthenticated target communication fra...
CVE-2025-53093HIGH8.6TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Starting in version 3.0.0 and prior to version ...
CVE-2025-6521HIGH7.6During the initial setup of the device the user connects to an access point broadcast by the Sight Bulb Pro. During the...
CVE-2025-52207CRITICAL9.9PBXCoreREST/Controllers/Files/PostController.php in MikoPBX through 2024.1.114 allows uploading a PHP script to an arbit...
CVE-2025-46708MEDIUM4.3Software installed and running inside a Guest VM may conduct improper GPU system calls to prevent other Guests from runn...
CVE-2025-46707MEDIUM5.2Software installed and running inside a Guest VM may override Firmware's state and gain access to the GPU.
CVE-2025-44559MEDIUM6.5An issue in the Bluetooth Low Energy (BLE) stack of Realtek RTL8762E BLE SDK v1.4.0 allows attackers within Bluetooth ra...
CVE-2025-44557HIGH8.1A state machine transition flaw in the Bluetooth Low Energy (BLE) stack of Cypress PSoC4 v3.66 allows attackers to bypas...
CVE-2025-50370MEDIUM6.5A Cross-Site Request Forgery (CSRF) vulnerability exists in the Inquiry Management functionality /mcgs/admin/readenq.php...
CVE-2025-50369MEDIUM6.5A Cross-Site Request Forgery (CSRF) vulnerability exists in the Manage Card functionality (/mcgs/admin/manage-card.php) ...
CVE-2025-50367MEDIUM6.1A stored blind XSS vulnerability exists in the Contact Page of the Phpgurukul Medical Card Generation System 1.0 mcgs/co...
CVE-2025-6705MEDIUM5.3A vulnerability in the Eclipse Open VSX Registry’s automated publishing system could have allowed unauthorized uploads o...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now