2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-36160HIGH7.5IBM Concert 1.0.0 through 2.0.0 could disclose sensitive server information from HTTP response headers that could aid in...
CVE-2025-13087HIGH7.5A vulnerability exists in the Opto22 Groov Manage REST API on GRV-EPIC and groov RIO Products that allows remote code ex...
CVE-2025-64770HIGH7The affected products allow unauthenticated access to Open Network Video Interface Forum (ONVIF) services, which may all...
CVE-2025-62674HIGH7The affected product allows unauthenticated access to Real Time Streaming Protocol (RTSP) services, which may allow an a...
CVE-2025-25613HIGH7.5FS Inc S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch, 8 x Gigabit RJ45, with 2 x 1Gb SFP, Fanless. All versions before 2...
CVE-2025-48986HIGH8.8Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change othe...
CVE-2025-63889HIGH7.5The fetch function in file thinkphp\library\think\Template.php in ThinkPHP 5.0.24 allows attackers to read arbitrary fil...
CVE-2025-62709HIGH8.8ClipBucket v5 is an open source video sharing platform. In ClipBucket version 5.5.2, a change to network.class.php cause...
CVE-2025-12121HIGH7.3Lite XL versions 2.1.8 and prior contain a vulnerability in the system.exec function, which allowed arbitrary command ex...
CVE-2025-12120HIGH7.3Lite XL versions 2.1.8 and prior automatically execute the .lite_project.lua file when opening a project directory, with...
CVE-2025-62730HIGH8.8SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to...
CVE-2025-62294HIGH7.5SOPlanning is vulnerable to Predictable Generation of Password Recovery Token. Due to weak mechanism of generating recov...
CVE-2025-41075HIGH7.5Vulnerability in LimeSurvey 6.13.0 in the endpoint /optin that causes infinite HTTP redirects when accessed directly. Th...
CVE-2025-41074HIGH7.5Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. ...
CVE-2025-40601HIGH7.5A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to ca...
CVE-2025-13468HIGH8.1A weakness has been identified in SourceCodester Alumni Management System 1.0. This issue affects the function delete_fo...
CVE-2025-13435HIGH8.1A security vulnerability has been detected in Dreampie Resty up to 1.3.1.SNAPSHOT. This affects the function Request of ...
CVE-2025-13434HIGH7.5A weakness has been identified in jameschz Hush Framework 2.0. The impacted element is an unknown function of the file H...
CVE-2025-13433HIGH7.3A security flaw has been discovered in Muse Group MuseHub 2.1.0.1567. The affected element is an unknown function of the...
CVE-2025-11676HIGH7.1Improper input validation vulnerability in TP-Link System Inc. TL-WR940N V6 (UPnP modules), which allows unauthenticated...
CVE-2025-0645HIGH7.2Unrestricted Upload of File with Dangerous Type vulnerability in Narkom Communication and Software Technologies Trade Lt...
CVE-2025-0643HIGH7.2Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Narkom Comm...
CVE-2025-13423HIGH7.2A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function ...
CVE-2025-11001HIGH7.87-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attacke...
CVE-2025-63719HIGH7.3Campcodes Online Hospital Management System 1.0 is vulnerable to SQL Injection in /admin/index.php via the parameter use...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now