2025 CVE Vulnerabilities

45,277 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-5543MEDIUM4.8A vulnerability was found in TOTOLINK X2000R 1.0.0-B20230726.1108. It has been declared as problematic. Affected by this...
CVE-2025-24015MEDIUM5.3Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions 1.46.0 through 2.1.6 have an issue that affects AES-...
CVE-2025-5542MEDIUM4.8A vulnerability was found in TOTOLINK X2000R 1.0.0-B20230726.1108. It has been classified as problematic. Affected is an...
CVE-2025-5527HIGH8.8A vulnerability was found in Tenda RX3 16.03.13.11_multi_TDE01. It has been rated as critical. This issue affects the fu...
CVE-2025-49002CRITICAL9.8DataEase is an open source business intelligence and data visualization tool. Versions prior to version 2.10.10 have a f...
CVE-2025-49001CRITICAL9.8DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.10, secret verificat...
CVE-2025-49000MEDIUM5.7InvenTree is an Open Source Inventory Management System. Prior to version 0.17.13, the skip field in the built-in `label...
CVE-2025-48999HIGH8.8DataEase is an open source business intelligence and data visualization tool. A bypass of CVE-2025-46566's patch exists ...
CVE-2025-48951CRITICAL9.3Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. Versions 8.0.0-BETA3 prior to 8.3.1 contain a vulne...
CVE-2025-5525HIGH8.1A vulnerability was found in Jrohy trojan up to 2.15.3. It has been declared as critical. This vulnerability affects the...
CVE-2025-5523MEDIUM6.1A vulnerability classified as problematic has been found in enilu web-flash 1.0. This affects the function fileService.u...
CVE-2025-35036HIGH7.3Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input...
CVE-2025-23100HIGH7.5An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. The absence of a NULL check lea...
CVE-2025-23098HIGH7.8An issue was discovered in Samsung Mobile Processor Exynos 980, 990, 1080, 2100, 1280, 2200, 1380. A Use-After-Free in t...
CVE-2025-23097CRITICAL9.1An issue was discovered in Samsung Mobile Processor Exynos 1380. The lack of a length check leads to out-of-bounds write...
CVE-2025-5522HIGH7.3A vulnerability was found in jack0240 魏 bskms 蓝天幼儿园管理系统 up to dffe6640b5b54d8e29da6f060e0493fea74b3fad. It has been rate...
CVE-2025-5521HIGH8.8A vulnerability was found in WuKongOpenSource WukongCRM 9.0. It has been declared as problematic. Affected by this vulne...
CVE-2025-48998HIGH8.8DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass of the p...
CVE-2025-48997HIGH8.7Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1...
CVE-2025-48953MEDIUM6.5Umbraco is an ASP.NET content management system (CMS). Starting in version 14.0.0 and prior to versions 15.4.2 and 16.0....
CVE-2025-48950HIGH8.8MaxKB is an open-source AI assistant for enterprise. Prior to version 1.10.8-lts, Sandbox only restricts the execution p...
CVE-2025-23102HIGH8.8An issue was discovered in Samsung Mobile Processor Exynos 980, 990, 1080, 2100, 1280, 2200, 1380, 1480 and 2400. A Doub...
CVE-2025-5520MEDIUM6.9A vulnerability was found in Open5GS up to 2.7.3. It has been classified as problematic. Affected is the function gmm_st...
CVE-2025-5516MEDIUM4.8A vulnerability, which was classified as problematic, was found in TOTOLINK X2000R 1.0.0-B20230726.1108. This affects an...
CVE-2025-5515MEDIUM6.3A vulnerability, which was classified as critical, has been found in TOTOLINK X2000R 1.0.0-B20230726.1108. Affected by t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now