2025 CVE Vulnerabilities

45,296 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-30100HIGH7.8Dell Alienware Command Center 6.x, versions prior to 6.7.37.0 contain an Improper Access Control Vulnerability. A low pr...
CVE-2025-32385MEDIUM6.5EspoCRM is an Open Source Customer Relationship Management software. Prior to 9.0.5, Iframe dashlet allows user to displ...
CVE-2025-30215CRITICAL9.6NATS-Server is a High-Performance server for NATS.io, the cloud and edge native messaging system. In versions starting f...
CVE-2025-32435LOW2.6Hydra is a Continuous Integration service for Nix based projects. Evaluation of untrusted non-flake nix code could poten...
CVE-2025-32388MEDIUM5.4SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.20.6 , unsa...
CVE-2025-25458MEDIUM4.6Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2.
CVE-2025-25453MEDIUM4.6Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serviceName2.
CVE-2025-22911MEDIUM5.6RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formiNICbasicREP function.
CVE-2025-32923HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GoodLayers Tourmas...
CVE-2025-32784HIGH7.5conda-forge-webservices is the web app deployed to run conda-forge admin commands and linting. In versions prior to 2025...
CVE-2025-32782MEDIUM5.3Ash Authentication provides authentication for the Ash framework. The confirmation flow for account creation currently u...
CVE-2025-31950MEDIUM6.9An unauthenticated attacker can obtain EV charger energy consumption information of other users.
CVE-2025-31945MEDIUM6.9An unauthenticated attacker can obtain other users' charger information.
CVE-2025-31654MEDIUM6.9An attacker can get information about the groups of the smart home devices for arbitrary users (i.e., "rooms").
CVE-2025-31360HIGH7.5Unauthenticated attackers can trigger device actions associated with specific "scenes" of arbitrary users.
CVE-2025-31147MEDIUM6.9Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users.
CVE-2025-30984HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dzynit SEO Tools s...
CVE-2025-30982MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookPr...
CVE-2025-30970HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in scottwallick Easy ...
CVE-2025-30967CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Upload a Web Shell to a Web Server. This i...
CVE-2025-30966MEDIUM5.4Path Traversal vulnerability in NotFound WPJobBoard allows Path Traversal. This issue affects WPJobBoard: from n/a throu...
CVE-2025-30512MEDIUM6.9Unauthenticated attackers can send configuration settings to device and possible perform physical actions remotely (e.g....
CVE-2025-30510CRITICAL9.8An attacker can upload an arbitrary file instead of a plant image.
CVE-2025-30257MEDIUM6.9Unauthenticated attackers can retrieve serial number of smart meters associated to a specific user account.
CVE-2025-29471HIGH8.3Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now