2025 CVE Vulnerabilities

45,266 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-53200MEDIUM4.3Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Cont...
CVE-2025-53199MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Slid...
CVE-2025-53197MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in cookiebot Cookiebot cookiebot allows Cross Site Request Forgery.This ...
CVE-2025-53193MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Burst Statistics B.V. Burst Statistics burst-statistics allows Cross ...
CVE-2025-52993MEDIUM5.6A race condition in the Nix, Lix, and Guix package managers enables changing the ownership of arbitrary files to the UID...
CVE-2025-52992LOW3.2The Nix, Lix, and Guix package managers fail to properly set permissions when a derivation build fails. This may allow a...
CVE-2025-52991LOW3.2The Nix, Lix, and Guix package managers default to using temporary build directories in a world-readable and world-writa...
CVE-2025-50528HIGH7.3A buffer overflow vulnerability exists in the fromNatStaticSetting function of Tenda AC6 <=V15.03.05.19 via the page par...
CVE-2025-46416LOW2.9The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges t...
CVE-2025-46415LOW3.2A race condition in the Nix, Lix, and Guix package managers allows the removal of content from arbitrary folders. This a...
CVE-2025-45729MEDIUM6.3D-Link DIR-823-Pro 1.02 has improper permission control, allowing unauthorized users to turn on and access Telnet servic...
CVE-2025-44163MEDIUM6.3RaspAP raspap-webgui 3.3.1 is vulnerable to Directory Traversal in ajax/networking/get_wgkey.php. An authenticated attac...
CVE-2025-36595HIGH7.2Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Directives in Statically ...
CVE-2025-6767MEDIUM6.3A vulnerability was found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. It has been rated as cr...
CVE-2025-6766HIGH8.8A vulnerability was found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. It has been declared as...
CVE-2025-53018LOW3Lychee is a free, open-source photo-management tool. Prior to version 6.6.13, a critical Server-Side Request Forgery (SS...
CVE-2025-40910MEDIUM6.5Net::IP::LPM version 1.10 for Perl does not properly consider leading zero characters in IP CIDR address strings, which ...
CVE-2025-6765HIGH8.8A vulnerability, which was classified as critical, has been found in Intelbras InControl 2.21.60.9. This issue affects s...
CVE-2025-6763HIGH8.2A vulnerability was found in Comet System T0510, T3510, T3511, T4511, T6640, T7511, T7611, P8510, P8552 and H3531 1.60. ...
CVE-2025-6762HIGH7.2A vulnerability classified as critical has been found in diyhi bbs up to 6.8. This affects the function getUrl of the fi...
CVE-2025-52834CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in favethemes Homey h...
CVE-2025-52829CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DirectIQ DirectIQ ...
CVE-2025-52827HIGH8.8Deserialization of Untrusted Data vulnerability in uxper Nuss nuss allows Object Injection.This issue affects Nuss: from...
CVE-2025-52826HIGH8.8Deserialization of Untrusted Data vulnerability in uxper Sala allows Object Injection. This issue affects Sala: from n/a...
CVE-2025-52824HIGH8.8Missing Authorization vulnerability in MDJM Mobile DJ Manager mobile-dj-manager allows Exploiting Incorrectly Configured...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now