2025 CVE Vulnerabilities

45,268 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-28382HIGH7.5An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory travers...
CVE-2025-28381HIGH7.5A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables...
CVE-2025-28380MEDIUM6.1A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scri...
CVE-2025-46096MEDIUM6.1Directory Traversal vulnerability in solon v.3.1.2 allows a remote attacker to conduct XSS attacks via the solon-faas-lu...
CVE-2025-46060CRITICAL9.8Buffer Overflow vulnerability in TOTOLINK N600R v4.3.0cu.7866_B2022506 allows a remote attacker to execute arbitrary cod...
CVE-2025-45988CRITICAL9.8Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26...
CVE-2025-45987CRITICAL9.8Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26...
CVE-2025-45986CRITICAL9.8Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26...
CVE-2025-45985CRITICAL9.8Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26...
CVE-2025-45984CRITICAL9.8Blink routers BL-WR9000 V2.4.9, BL-AC1900 V1.0.2, BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 V1.0.5, BL-LTE300 V1.2.3, BL-F1200_AT...
CVE-2025-49468HIGH8.6A SQL injection vulnerability in No Boss Calendar component before 5.0.7 for Joomla was discovered. The vulnerability al...
CVE-2025-29902CRITICAL10Remote code execution that allows unauthorized users to execute arbitrary code on the server machine.
CVE-2025-48825LOW2.5RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.7.0 contains an issue with use of less trusted source, which may al...
CVE-2025-46783CRITICAL9.8Path traversal vulnerability exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If this vulnerability...
CVE-2025-36506MEDIUM6.9External control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If an ...
CVE-2025-6012MEDIUM5.5The Auto Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version...
CVE-2025-39240HIGH7.2Some Hikvision Wireless Access Point are vulnerable to authenticated remote command execution due to insufficient input ...
CVE-2025-5923MEDIUM6.4The Game Review Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in...
CVE-2025-22242MEDIUM5.6Worker process denial of service through file read operation. .A vulnerability exists in the Master's “pub_ret” method w...
CVE-2025-22241MEDIUM5.6File contents overwrite the VirtKey class is called when “on-demand pillar” data is requested and uses un-validated inpu...
CVE-2025-22240MEDIUM6.3Arbitrary directory creation or file deletion. In the find_file method of the GitFS class, a path is created using os.pa...
CVE-2025-22239HIGH8.1Arbitrary event injection on Salt Master. The master's "_minion_event" method can be used by and authorized minion to se...
CVE-2025-22238MEDIUM4.2Directory traversal attack in minion file cache creation. The master's default cache is vulnerable to a directory traver...
CVE-2025-22237MEDIUM6.7An attacker with access to a minion key can exploit the 'on demand' pillar functionality with a specially crafted git ur...
CVE-2025-22236HIGH8.1Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now