2025 CVE Vulnerabilities

45,266 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-6707MEDIUM5.4Under certain conditions, an authenticated user request may execute with stale privileges following an intentional chang...
CVE-2025-6706HIGH8.8An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior...
CVE-2025-6695MEDIUM4.1A vulnerability was found in LabRedesCefetRJ WeGIA 3.4.0 and classified as problematic. This issue affects some unknown ...
CVE-2025-6694MEDIUM4.1A vulnerability has been found in LabRedesCefetRJ WeGIA 3.4.0 and classified as problematic. This vulnerability affects ...
CVE-2025-6677MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Paragraphs ...
CVE-2025-6676MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple XML ...
CVE-2025-6675MEDIUM4.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows ...
CVE-2025-6674MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor5 Y...
CVE-2025-5682MEDIUM4.3Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Klaro Cooki...
CVE-2025-52573MEDIUM6iOS Simulator MCP Server (ios-simulator-mcp) is a Model Context Protocol (MCP) server for interacting with iOS simulator...
CVE-2025-49003CRITICAL9.8DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, a threat actor m...
CVE-2025-48923MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Toc.Js allo...
CVE-2025-48922MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal GLightbox a...
CVE-2025-48921HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Drupal Open Social allows Cross Site Request Forgery.This issue affec...
CVE-2025-6693HIGH8.5A vulnerability, which was classified as critical, was found in RT-Thread up to 5.1.0. This affects the function sys_dev...
CVE-2025-6562HIGH8.8Certain hybrid DVR models (HBF-09KD and HBF-16NK) from Hunt Electronic have an OS Command Injection vulnerability, allow...
CVE-2025-5966HIGH8.1Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by f...
CVE-2025-5366HIGH8.1Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Folder-wise read...
CVE-2025-6561CRITICAL9.8Certain hybrid DVR models ((HBF-09KD and HBF-16NK)) from Hunt Electronic have an Exposure of Sensitive Information vulne...
CVE-2025-3773MEDIUM5.5A sensitive information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and prior allows an authentic...
CVE-2025-3771HIGH7.1A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin loc...
CVE-2025-3722MEDIUM4.4A path traversal vulnerability in System Information Reporter (SIR) 1.0.3 and prior allowed an authenticated high privi...
CVE-2025-6703MEDIUM6.5Improper Input Validation vulnerability in Mozilla neqo leads to an unexploitable crash..This issue affects neqo: from 0...
CVE-2025-6212MEDIUM6.1The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Database m...
CVE-2025-5842MEDIUM5.4The Modern Design Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now