2025 CVE Vulnerabilities

45,280 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-1079HIGH7.8Client RCE on macOS and Linux via improper symbolic link resolution in Google Web Designer's preview feature
CVE-2025-47682CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Al...
CVE-2025-44176MEDIUM6.5Tenda FH451 V1.0.0.9 is vulnerable to Remote Code Execution in the formSafeEmailFilter function.
CVE-2025-44175MEDIUM5.4Tenda AC10 v4 V16.03.10.13 is vulnerable to Buffer Overflow in the GetParentControlInfo function.
CVE-2025-46750MEDIUM4.4SEL BIOS packages prior to 1.3.49152.117 or 2.6.49152.98 allow a local attacker to bypass password authentication and ch...
CVE-2025-46749MEDIUM4.3An authenticated user could submit scripting to fields that lack proper input and output sanitization leading to subsequ...
CVE-2025-46748LOW2.7An authenticated user attempting to change their password could do so without using the current password.
CVE-2025-46747MEDIUM5.7An authenticated user without user-management permissions could identify other user accounts.
CVE-2025-46746MEDIUM5.8An administrator could discover another account's credentials.
CVE-2025-46745MEDIUM6.5An authenticated user without user-management permissions could view other users account information.
CVE-2025-46744LOW2.7An authenticated administrator could modify the Created By username for a user account
CVE-2025-46743MEDIUM6.3An authenticated user's token could be used by another source after the user had logged out prior to the token expiring.
CVE-2025-46742MEDIUM4.3Users who were required to change their password could still access system information before changing their password
CVE-2025-46741MEDIUM5.7A suspended or recently logged-out user could continue to interact with Blueframe until the time-out period occurred.
CVE-2025-46740HIGH7.5An authenticated user without user administrative permissions could change the administrator Account Name.
CVE-2025-46739HIGH8.1An unauthenticated user could discover account credentials via a brute-force attack without rate limiting
CVE-2025-45779CRITICAL9.8Tenda AC10 V1.0re_V15.03.06.46 is vulnerable to Buffer Overflow in the formSetPPTPUserList handler via the list POST par...
CVE-2025-3632HIGH7.5IBM 4769 Developers Toolkit 7.0.0 through 7.5.52 could allow a remote attacker to cause a denial of service in the Hardw...
CVE-2025-47578MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edward Caissie BNS...
CVE-2025-46738MEDIUM6.6An authenticated attacker can maliciously modify layout data files in the SEL-5033 installation directory to execute arb...
CVE-2025-46737HIGH7.4SEL-5037 Grid Configurator contains an overly permissive Cross Origin Resource Sharing (CORS) configuration for a data g...
CVE-2025-44830CRITICAL9.8EngineerCMS v1.02 through v.2.0.5 has a SQL injection vulnerability in the /project/addprojtemplet interface.
CVE-2025-44022CRITICAL9.8An issue in vvveb CMS v.1.0.6 allows a remote attacker to execute arbitrary code via the Plugin mechanism.
CVE-2025-47274LOW2.4ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Due to...
CVE-2025-46718LOW3.3sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with limited sudo ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now