2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-65552CRITICAL9.8D3D Wi-Fi Home Security System ZX-G12 v2.1.1 is vulnerable to RF replay attacks on the 433 MHz sensor communication chan...
CVE-2025-41078HIGH8.1Weaknesses in the authorization mechanisms of Viafirma Documents v3.7.129 allow an authenticated user without privileges...
CVE-2025-41077HIGH8.1IDOR vulnerability has been found in Viafirma Inbox v4.5.13 that allows any authenticated user without privileges in the...
CVE-2025-41006CRITICAL9.3Imaster's MEMS Events CRM contains an SQL injection vulnerability in ‘phone’ parameter in ‘/memsdemo/login.php’.
CVE-2025-41005HIGH8.7Imaster's MEMS Events CRM contains an SQL injection vulnerability in‘keyword’ parameter in ‘/memsdemo/exchange_offers.ph...
CVE-2025-41004HIGH8.7Imaster's Patient Records Management System is vulnerable to SQL Injection in the endpoint ‘/projects/hospital/admin/com...
CVE-2025-41003MEDIUM5.1Imaster's Patient Record Management System contains a stored Cross-Site Scripting (XSS) vulnerability in the endpoint ‘/...
CVE-2025-40978MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's eCommerceGo SaaS, consisting of a stored XSS due to a lack o...
CVE-2025-40977MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's eCommerceGo SaaS, consisting of a lack of proper validation ...
CVE-2025-40976MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's TicketGo, consisting of a lack of proper validation of user ...
CVE-2025-40975MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's HRMGo, consisting of a lack of proper validation of user inp...
CVE-2025-14279HIGH8.1MLFlow versions up to and including 3.4.0 are vulnerable to DNS rebinding attacks due to a lack of Origin header validat...
CVE-2025-14579MEDIUM4.8The Quiz Maker WordPress plugin before 6.7.0.89 does not sanitise and escape some of its settings, which could allow hig...
CVE-2025-69276HIGH8.8Deserialization of Untrusted Data vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Object Injection...
CVE-2025-69275MEDIUM6.1Dependency on Vulnerable Third-Party Component vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows DOM...
CVE-2025-69274HIGH8.8Authorization Bypass Through User-Controlled Key vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows P...
CVE-2025-69273HIGH7.5Improper Authentication vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Authentication Bypass.This...
CVE-2025-69272HIGH7.5Cleartext Transmission of Sensitive Information vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sn...
CVE-2025-69271HIGH7.5Insufficiently Protected Credentials vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Atta...
CVE-2025-69270CRITICAL9.8Information Exposure Through Query Strings in GET Request vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux...
CVE-2025-69269CRITICAL9.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Broadcom DX ...
CVE-2025-69268MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Broadcom DX...
CVE-2025-69267MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in Broadcom DX NetOps Spectru...
CVE-2025-52694CRITICAL9.8Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arb...
CVE-2025-68493HIGH8.1Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 befo...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now