2025 CVE Vulnerabilities

45,269 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-41366MEDIUM5.1In IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04, a configuration error has been detected in cross-origin resource sharing...
CVE-2025-41365MEDIUM5.1Code injection vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability allows an attacker to st...
CVE-2025-41364MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability allow...
CVE-2025-41363MEDIUM5.3In IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04, a configuration error has been detected in cross-origin resource sharing...
CVE-2025-41362MEDIUM5.3Code injection vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability allows an attacker to st...
CVE-2025-41361HIGH8.3Uncontrolled resource consumption vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. The devices improperly h...
CVE-2025-41360HIGH8.7Uncontrolled resource consumption vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. The device is vulnerable...
CVE-2025-39358HIGH8.8Deserialization of Untrusted Data vulnerability in teastudio.pl WP Posts Carousel wp-posts-carousel allows Object Inject...
CVE-2025-5759CRITICAL9.8A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. This ...
CVE-2025-5758HIGH7.3A vulnerability classified as critical has been found in SourceCodester Open Source Clinic Management System 1.0. This a...
CVE-2025-5757MEDIUM5.4A vulnerability was found in code-projects Traffic Offense Reporting System 1.0. It has been rated as problematic. Affec...
CVE-2025-5756CRITICAL9.8A vulnerability was found in code-projects Real Estate Property Management System 1.0. It has been declared as critical....
CVE-2025-5755HIGH7.3A vulnerability was found in SourceCodester Open Source Clinic Management System 1.0. It has been classified as critical...
CVE-2025-5192HIGH7.5A missing authentication for critical function vulnerability in the client application of Soar Cloud HRD Human Resource ...
CVE-2025-48784HIGH7.5A missing authorization vulnerability in Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 a...
CVE-2025-48783HIGH7.5An external control of file name or path vulnerability in the delete file function of Soar Cloud HRD Human Resource Mana...
CVE-2025-48782CRITICAL9.8An unrestricted upload of file with dangerous type vulnerability in the upload file function of Soar Cloud HRD Human Res...
CVE-2025-48781HIGH7.5An external control of file name or path vulnerability in the download file function of Soar Cloud HRD Human Resource Ma...
CVE-2025-48780CRITICAL9.8A deserialization of untrusted data vulnerability in the download file function of Soar Cloud HRD Human Resource Managem...
CVE-2025-5739HIGH8.8A vulnerability classified as critical has been found in TOTOLINK X15 1.0.0-B20230714.1105. This affects an unknown part...
CVE-2025-5738HIGH8.8A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been rated as critical. Affected by this issue is...
CVE-2025-5737HIGH8.8A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. Affected by this vulne...
CVE-2025-3365CRITICAL9.8A missing protection against path traversal allows to access any file on the server.
CVE-2025-3322CRITICAL10An improper neutralization of inputs used in expression language allows remote code execution with the highest privilege...
CVE-2025-5736HIGH8.8A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as critical. Affected is an unkno...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now