2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-67858HIGH7A Improper Neutralization of Argument Delimiters vulnerability in Foomuuri can lead to integrity loss of the firewall co...
CVE-2025-67091MEDIUM6.5An issue in GL Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. GL.Inet AX1800 Version 4.6.4 & 4.6.8 in the GL....
CVE-2025-67090MEDIUM5.1The LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL...
CVE-2025-67089HIGH8.1A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present ...
CVE-2025-63611HIGH8.7Cross-Site Scripting in phpgurukul Hostel Management System v2.1 user-provided complaint fields (Explain the Complaint) ...
CVE-2025-67603MEDIUM5.1A Improper Authorization vulnerability in Foomuuri llows arbitrary users to influence the firewall configuration.This is...
CVE-2025-66003HIGH7.3An External Control of File Name or Path vulnerability in smb4k allowsl ocal users to perform a local root exploit via s...
CVE-2025-66002MEDIUM6.9An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability allows local users ...
CVE-2025-4596MEDIUM5.3Asseco ADMX system is used for processing medical records. It allows logged in users to access medical files belonging t...
CVE-2025-8307MEDIUM5.9Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sec...
CVE-2025-8306MEDIUM5.1Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sec...
CVE-2025-14025HIGH8.5A flaw was found in Ansible Automation Platform (AAP). Read-only scoped OAuth2 API Tokens in AAP, are enforced at the Ga...
CVE-2025-69260HIGH7.5A message out-of-bounds read vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-...
CVE-2025-69259HIGH7.5A message unchecked NULL return value vulnerability in Trend Micro Apex Central could allow a remote attacker to create ...
CVE-2025-69258CRITICAL9.8A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an atta...
CVE-2025-62877CRITICAL9.8Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password  if they are...
CVE-2025-66001HIGH8.8NeuVector supports login authentication through OpenID Connect. However, the TLS verification (which verifies the remote...
CVE-2025-69169MEDIUM5.4Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Noor Alam Easy Media Down...
CVE-2025-68892HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gopiplus@hotmail.c...
CVE-2025-68891HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Sutana WP App...
CVE-2025-68890HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hands01 e-shops e-...
CVE-2025-68889HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pinpoll Pinpoll pi...
CVE-2025-68887HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CMSJunkie - WordPr...
CVE-2025-68875MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jcaruso001 Flaming...
CVE-2025-68874HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shahjada Visitor S...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now