2025 CVE Vulnerabilities

45,266 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-6699MEDIUM4.1A vulnerability classified as problematic has been found in LabRedesCefetRJ WeGIA 3.4.0. This affects an unknown part of...
CVE-2025-51671MEDIUM5.4A SQL injection vulnerability was discovered in the PHPGurukul Dairy Farm Shop Management System 1.3. The vulnerability ...
CVE-2025-50350MEDIUM5.4PHPGurukul Pre-School Enrollment System Project v1.0 is vulnerable to Directory Traversal in manage-classes.php.
CVE-2025-44141MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in the node creation form of Backdrop CMS 1.30.
CVE-2025-36034MEDIUM5.9IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 discloses sensitive user information in...
CVE-2025-34049CRITICAL9.4An OS command injection vulnerability exists in the OptiLink ONT1GEW GPON router firmware version V2.1.11_X101 Build 112...
CVE-2025-34048HIGH8.7A path traversal vulnerability exists in the web management interface of D-Link DSL-2730U, DSL-2750U, and DSL-2750E ADSL...
CVE-2025-34047HIGH8.7A path traversal vulnerability exists in the Leadsec SSL VPN (formerly Lenovo NetGuard), allowing unauthenticated attack...
CVE-2025-34046CRITICAL10An unauthenticated file upload vulnerability exists in the Fanwei E-Office <= v9.4 web management interface. The vulnera...
CVE-2025-34045HIGH7.5A path traversal vulnerability exists in WeiPHP 5.0, an open source WeChat public account platform development framework...
CVE-2025-34044CRITICAL9.4A remote command injection vulnerability exists in the confirm.php interface of the WIFISKY 7-layer Flow Control Router ...
CVE-2025-34043CRITICAL10A remote command injection vulnerability exists in Vacron Network Video Recorder (NVR) devices v1.4 due to improper inpu...
CVE-2025-34042CRITICAL9.4An authenticated command injection vulnerability exists in the Beward N100 IP Camera firmware version M2.1.6.04C014 via ...
CVE-2025-6698MEDIUM4.1A vulnerability was found in LabRedesCefetRJ WeGIA 3.4.0. It has been rated as problematic. Affected by this issue is so...
CVE-2025-6697MEDIUM4.1A vulnerability was found in LabRedesCefetRJ WeGIA 3.4.0. It has been declared as problematic. Affected by this vulnerab...
CVE-2025-6696MEDIUM4.1A vulnerability was found in LabRedesCefetRJ WeGIA 3.4.0. It has been classified as problematic. Affected is an unknown ...
CVE-2025-53007HIGH8.9arduino-esp32 provides an Arduino core for the ESP32. Versions prior to 3.3.0-RC1 and 3.2.1 contain a HTTP Response Spli...
CVE-2025-53002CRITICAL9.8LLaMA-Factory is a tuning library for large language models. A remote code execution vulnerability was discovered in LLa...
CVE-2025-52902MEDIUM5.4File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ...
CVE-2025-52900MEDIUM5.5File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ...
CVE-2025-52887HIGH7.5cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In version 0.21.0, when many http head...
CVE-2025-51672HIGH8A time-based blind SQL injection vulnerability was identified in the PHPGurukul Dairy Farm Shop Management System 1.3. T...
CVE-2025-29331CRITICAL9.8An issue in MHSanaei 3x-ui before v.2.5.3 and before allows a remote attacker to execute arbitrary code via the manageme...
CVE-2025-6710HIGH7.5MongoDB Server may be susceptible to stack overflow due to JSON parsing mechanism, where specifically crafted JSON input...
CVE-2025-6709HIGH7.5The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now