2025 CVE Vulnerabilities

45,268 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-40675MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability has been found in Bagisto v2.0.0. This vulnerability allows an atta...
CVE-2025-5870HIGH7.3A vulnerability has been found in TRENDnet TV-IP121W 1.1.1 Build 36 and classified as critical. Affected by this vulnera...
CVE-2025-5869CRITICAL9.8A vulnerability, which was classified as critical, was found in RT-Thread 5.1.0. Affected is the function sys_recvfrom o...
CVE-2025-5894HIGH8.8Smart Parking Management System from Honding Technology has a Missing Authorization vulnerability, allowing remote attac...
CVE-2025-5868CRITICAL9.8A vulnerability, which was classified as critical, has been found in RT-Thread 5.1.0. This issue affects the function sy...
CVE-2025-5867CRITICAL9.8A vulnerability classified as critical was found in RT-Thread 5.1.0. This vulnerability affects the function csys_sendto...
CVE-2025-5893CRITICAL9.8Smart Parking Management System from Honding Technology has an Exposure of Sensitive Information vulnerability, allowing...
CVE-2025-5866CRITICAL9.8A vulnerability classified as critical has been found in RT-Thread 5.1.0. This affects the function sys_sigprocmask of t...
CVE-2025-5865CRITICAL9.8A vulnerability was found in RT-Thread 5.1.0. It has been rated as critical. Affected by this issue is the function sys_...
CVE-2025-5864LOW3.7A vulnerability was found in Tenda TDSEE App up to 1.7.12. It has been declared as problematic. Affected by this vulnera...
CVE-2025-5863CRITICAL9.8A vulnerability was found in Tenda AC5 15.03.06.47. It has been classified as critical. Affected is the function formSet...
CVE-2025-4652MEDIUM6.1The Broadstreet WordPress plugin before 1.51.8 does not sanitise and escape a parameter before outputting it back in the...
CVE-2025-47712MEDIUM6.5A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request. When a client...
CVE-2025-47711MEDIUM6.5There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a c...
CVE-2025-3582MEDIUM4.8The Newsletter WordPress plugin before 8.85 does not sanitise and escape some of its Form settings, which could allow h...
CVE-2025-3581MEDIUM4.8The Newsletter WordPress plugin before 8.8.5 does not validate and escape some of its Widget options before outputting ...
CVE-2025-25209MEDIUM5.7The AuthPolicy metadata on Red Hat Connectivity Link contains an object which stores secretes, however it assumes those ...
CVE-2025-25208MEDIUM5.7A Developer persona can bring down the Authorino service, preventing the evaluation of all AuthPolicies on the cluster
CVE-2025-25207MEDIUM5.7The Authorino service in the Red Hat Connectivity Link is the authorization service for zero trust API security. Authori...
CVE-2025-5862CRITICAL9.8A vulnerability was found in Tenda AC7 15.03.06.44 and classified as critical. This issue affects the function formSetPP...
CVE-2025-5861CRITICAL9.8A vulnerability has been found in Tenda AC7 15.03.06.44 and classified as critical. This vulnerability affects the funct...
CVE-2025-5860CRITICAL9.8A vulnerability, which was classified as critical, was found in PHPGurukul Maid Hiring Management System 1.0. This affec...
CVE-2025-5859HIGH8.8A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been declared as critical. Aff...
CVE-2025-5858HIGH8.8A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been classified as critical. A...
CVE-2025-5857HIGH8.8A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. This issue a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now