2025 CVE Vulnerabilities

45,266 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-34041CRITICAL10An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) ma...
CVE-2025-34040CRITICAL10An arbitrary file upload vulnerability exists in the Zhiyuan OA platform via the wpsAssistServlet interface. The realFil...
CVE-2025-34039CRITICAL10A code injection vulnerability exists in Yonyou UFIDA NC v6.5 and prior due to the exposure of the BeanShell testing ser...
CVE-2025-34038HIGH7.5A SQL injection vulnerability exists in Weaver E-cology 8.0 via the getdata.jsp endpoint. The application directly passe...
CVE-2025-6535HIGH8.8A vulnerability has been found in xxyopen/201206030 novel-plus up to 5.1.3 and classified as critical. This vulnerabilit...
CVE-2025-6534MEDIUM6.8A vulnerability, which was classified as problematic, was found in xxyopen/201206030 novel-plus up to 5.1.3. This affect...
CVE-2025-34037CRITICAL10An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /h...
CVE-2025-34036CRITICAL9.8An OS command injection vulnerability exists in white-labeled DVRs manufactured by TVT, affecting a custom HTTP service ...
CVE-2025-34035CRITICAL9.8An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. The usbintera...
CVE-2025-34034HIGH8.8A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems. The app...
CVE-2025-34033HIGH8.8An OS command injection vulnerability exists in the Blue Angel Software Suite running on embedded Linux devices via the ...
CVE-2025-34032MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the ...
CVE-2025-34031HIGH7.5A path traversal vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the query parameter in jsm...
CVE-2025-6533MEDIUM5.9A vulnerability, which was classified as critical, has been found in xxyopen/201206030 novel-plus up to 5.1.3. Affected ...
CVE-2025-6532MEDIUM4.3A vulnerability classified as problematic was found in NOYAFA/Xiami LF9 Pro up to 20250611. Affected by this vulnerabili...
CVE-2025-6531MEDIUM4.3A vulnerability was found in SIFUSM/MZZYG BD S1 up to 20250611. It has been declared as problematic. This vulnerability ...
CVE-2025-6530MEDIUM4.8A vulnerability was found in 70mai M300 up to 20250611. It has been classified as problematic. This affects an unknown p...
CVE-2025-6529HIGH8.8A vulnerability was found in 70mai M300 up to 20250611 and classified as critical. Affected by this issue is some unknow...
CVE-2025-6528MEDIUM4.3A vulnerability has been found in 70mai M300 up to 20250611 and classified as problematic. Affected by this vulnerabilit...
CVE-2025-6527LOW3.1A vulnerability, which was classified as problematic, was found in 70mai M300 up to 20250611. Affected is an unknown fun...
CVE-2025-6526MEDIUM5.3A vulnerability, which was classified as problematic, has been found in 70mai M300 up to 20250611. This issue affects so...
CVE-2025-6525MEDIUM4.3A vulnerability classified as problematic was found in 70mai 1S up to 20250611. This vulnerability affects unknown code ...
CVE-2025-6524LOW3.1A vulnerability classified as problematic has been found in 70mai 1S up to 20250611. This affects an unknown part of the...
CVE-2025-52562CRITICAL10Convoy is a KVM server management panel for hosting businesses. In versions 3.9.0-rc3 to before 4.4.1, there is a direct...
CVE-2025-52561MEDIUM6.9HTMLSanitizer.jl is a Whitelist-based HTML sanitizer. Prior to version 0.2.1, when adding the style tag to the whitelist...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now