2025 CVE Vulnerabilities

45,268 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-46035HIGH7.5Buffer Overflow vulnerability in Tenda AC6 v.15.03.05.16 allows a remote attacker to cause a denial of service via the o...
CVE-2025-36573MEDIUM5.5Dell Smart Dock Firmware, versions prior to 01.00.08.01, contain an Insertion of Sensitive Information into Log File vul...
CVE-2025-29744MEDIUM5.4pg-promise before 11.5.5 is vulnerable to SQL Injection due to improper handling of negative numbers.
CVE-2025-49200HIGH7.5The created backup files are unencrypted, making the application vulnerable for gathering sensitive information by downl...
CVE-2025-49199CRITICAL9.8The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP...
CVE-2025-49198HIGH7.5The Media Server’s authorization tokens have a poor quality of randomness. An attacker may be able to guess the token of...
CVE-2025-49197HIGH7.5The application uses a weak password hash function, allowing an attacker to crack the weak password hash to gain access ...
CVE-2025-49196CRITICAL9.1A service supports the use of a deprecated and unsafe TLS version. This could be exploited to expose sensitive informati...
CVE-2025-49195CRITICAL9.8The FTP server’s login mechanism does not restrict authentication attempts, allowing an attacker to brute-force user pas...
CVE-2025-49194HIGH7.5The server supports authentication methods in which credentials are sent in plaintext over unencrypted channels. If an a...
CVE-2025-49193MEDIUM6.1The application fails to implement several security headers. These headers help increase the overall security level of t...
CVE-2025-49192MEDIUM6.1The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an atta...
CVE-2025-49191MEDIUM6.1Linked URLs during the creation of iFrame widgets and dashboards are vulnerable to code execution. The URLs get embedded...
CVE-2025-49190MEDIUM5.8The application is vulnerable to Server-Side Request Forgery (SSRF). An endpoint can be used to send server internal req...
CVE-2025-49189MEDIUM6.1The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via cl...
CVE-2025-49188HIGH7.5The application sends user credentials as URL parameters instead of POST bodies, making it vulnerable to information gat...
CVE-2025-49187MEDIUM5.3For failed login attempts, the application returns different error messages depending on whether the login failed due to...
CVE-2025-49186MEDIUM6.5The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short tim...
CVE-2025-49185MEDIUM5.4The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboard widgets can...
CVE-2025-49184HIGH7.5A remote unauthorized attacker may gather sensitive information of the application, due to missing authorization of conf...
CVE-2025-49183HIGH7.5All communication with the REST API is unencrypted (HTTP), allowing an attacker to intercept traffic between an actor an...
CVE-2025-49182CRITICAL9.8Files in the source code contain login credentials for the admin user and the property configuration password, allowing ...
CVE-2025-49181HIGH8.6Due to missing authorization of an API endpoint, unauthorized users can send HTTP GET requests to gather sensitive infor...
CVE-2025-6021HIGH7.5A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a ...
CVE-2025-5195MEDIUM4.3An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.7, 17.11 before 17.11.3, and ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now