2025 CVE Vulnerabilities

45,267 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-36632HIGH7.8In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could execute c...
CVE-2025-6123CRITICAL9.8A vulnerability has been found in code-projects Restaurant Order System 1.0 and classified as critical. This vulnerabili...
CVE-2025-6122HIGH8.8A vulnerability, which was classified as critical, was found in code-projects Restaurant Order System 1.0. This affects ...
CVE-2025-6121CRITICAL9.8A vulnerability, which was classified as critical, has been found in D-Link DIR-632 FW103B08. Affected by this issue is ...
CVE-2025-6120MEDIUM5.3A vulnerability classified as critical was found in Open Asset Import Library Assimp up to 5.4.3. Affected by this vulne...
CVE-2025-5689HIGH8.5A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the fir...
CVE-2025-46710MEDIUM5.7Possible kernel exceptions caused by reading and writing kernel heap data after free.
CVE-2025-24388LOW3.8A vulnerability in the OTRS Admin Interface and Agent Interface (versions before OTRS 8) allow parameter injection due t...
CVE-2025-6119MEDIUM5.3A vulnerability classified as critical has been found in Open Asset Import Library Assimp up to 5.4.3. Affected is the f...
CVE-2025-6118CRITICAL9.8A vulnerability was found in Das Parking Management System 停车场管理系统 6.2.0. It has been rated as critical. This issue affe...
CVE-2025-4748MEDIUM4.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (stdlib modul...
CVE-2025-47869CRITICAL9.8Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability was discovered in Apache NuttX RTO...
CVE-2025-47868CRITICAL9.8Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter...
CVE-2025-40916CRITICAL9.1Mojolicious::Plugin::CaptchaPNG version 1.05 for Perl uses a weak random number source for generating the captcha. That...
CVE-2025-6117CRITICAL9.8A vulnerability was found in Das Parking Management System 停车场管理系统 6.2.0. It has been declared as critical. This vulnera...
CVE-2025-6116CRITICAL9.8A vulnerability was found in Das Parking Management System 停车场管理系统 6.2.0. It has been classified as critical. This affec...
CVE-2025-25265MEDIUM4.9A web application for configuring the controller is accessible at a specific path. It contains an endpoint that allows a...
CVE-2025-25264MEDIUM6.5An unauthenticated remote attacker can trick an admin to visit a website containing malicious java script code. The curr...
CVE-2025-6172CRITICAL9.8Permission vulnerability in the mobile application (com.afmobi.boomplayer) may lead to the risk of unauthorized operatio...
CVE-2025-6115HIGH8.8A vulnerability was found in D-Link DIR-619L 2.06B01 and classified as critical. Affected by this issue is the function ...
CVE-2025-6114HIGH8.8A vulnerability has been found in D-Link DIR-619L 2.06B01 and classified as critical. Affected by this vulnerability is ...
CVE-2025-40729MEDIUM6.1Reflected Cross-Site Scripting (XSS) in /customer_support/index.php in Customer Support System v1.0, which allows remote...
CVE-2025-40728HIGH8.8SQL injection vulnerability in Customer Support System v1.0. This vulnerability allows an authenticated attacker to retr...
CVE-2025-40727MEDIUM5.1A Reflected Cross Site Scripting (XSS) vulnerability was found in '/search' in Phoenix Site CMS from Phoenix, which allo...
CVE-2025-40726MEDIUM5.1Reflected Cross-Site Scripting (XSS) vulnerability in /pages/search-results-page in Nosto, which allows remote attackers...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now