2025 CVE Vulnerabilities

45,277 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-5607HIGH8.8A vulnerability was found in Tenda AC18 15.03.05.05. It has been rated as critical. This issue affects the function form...
CVE-2025-48935CRITICAL9.1Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 2.2.0 and prior to versions 2.2.5, it is ...
CVE-2025-48934MEDIUM5.3Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to versions 2.1.13 and 2.2.13, the `Deno.env.toObject` ...
CVE-2025-48888MEDIUM5.3Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.41.3 and prior to versions 2.1.13, 2.2....
CVE-2025-46339MEDIUM4.3FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, it's possible to poison feed favicons by adding ...
CVE-2025-46204MEDIUM6.5An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /course/edit/{id} endpoint.
CVE-2025-46203MEDIUM6.5An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /students/edit/{id} endpoint.
CVE-2025-46011MEDIUM6.5Listmonk v4.1.0 (fixed in v5.0.0) is vulnerable to SQL Injection in the QuerySubscribers function which allows attackers...
CVE-2025-32015MEDIUM6.7FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, HTML is sanitized improperly inside the `<iframe...
CVE-2025-31482MEDIUM4.3FreshRSS is a self-hosted RSS feed aggregator. A vulnerability in versions prior to 1.26.2 causes a user to be repeatedl...
CVE-2025-31136MEDIUM5.4FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, it's possible to run arbitrary JavaScript on the...
CVE-2025-31134HIGH7.5FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, an attacker can gain additional information abou...
CVE-2025-22245MEDIUM5.9VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validatio...
CVE-2025-22244MEDIUM6.9VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input vali...
CVE-2025-22243HIGH7.5VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation.
CVE-2025-5606CRITICAL9.8A vulnerability was found in Tenda AC18 15.03.05.05. It has been declared as critical. This vulnerability affects the fu...
CVE-2025-5604CRITICAL9.8A vulnerability was found in Campcodes Hospital Management System 1.0 and classified as critical. Affected by this issue...
CVE-2025-5603CRITICAL9.8A vulnerability has been found in Campcodes Hospital Management System 1.0 and classified as critical. Affected by this ...
CVE-2025-5602CRITICAL9.8A vulnerability, which was classified as critical, was found in Campcodes Hospital Management System 1.0. Affected is an...
CVE-2025-5600CRITICAL9.8A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This issue...
CVE-2025-5599CRITICAL9.8A vulnerability classified as critical was found in PHPGurukul Student Result Management System 1.3. This vulnerability ...
CVE-2025-5688HIGH7.5We have identified a buffer overflow issue allowing out-of-bounds write when processing LLMNR or mDNS queries with very ...
CVE-2025-5596CRITICAL9.8A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. Affected is an unknown functi...
CVE-2025-5595CRITICAL9.8A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. This issue affects some unknown proces...
CVE-2025-2336MEDIUM4.8Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS's 'n...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now