2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-43706HIGH7.5An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 240...
CVE-2025-27807CRITICAL9.1An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128...
CVE-2025-65922MEDIUM4.3PLANKA 2.0.0 lacks X-Frame-Options and CSP frame-ancestors headers, allowing the application to be embedded within malic...
CVE-2025-61781CRITICAL9.1OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6....
CVE-2025-59955MEDIUM5.7Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions pri...
CVE-2025-59158HIGH8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions pri...
CVE-2025-59157HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0...
CVE-2025-59156HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0...
CVE-2025-55204CRITICAL9.6muffon is a cross-platform music streaming client for desktop. Versions prior to 2.3.0 have a one-click Remote Code Exec...
CVE-2025-67316MEDIUM5.4An issue in realme Internet browser v.45.13.4.1 allows a remote attacker to execute arbitrary code via a crafted webpage...
CVE-2025-59467CRITICAL9.6A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow p...
CVE-2025-57836HIGH7.8An issue was discovered in Samsung Magician 6.3.0 through 8.3.2 on Windows. The installer creates a temporary folder wit...
CVE-2025-53344MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in ThimPress Thim Core allows Cross Site Request Forgery.This issue affe...
CVE-2025-52519HIGH7.1An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, ...
CVE-2025-46255HIGH7.5Missing Authorization vulnerability in Marketing Fire LLC LoginWP - Pro allows Accessing Functionality Not Properly Cons...
CVE-2025-39561MEDIUM6.5Missing Authorization vulnerability in Marketing Fire, LLC LoginWP - Pro allows Accessing Functionality Not Properly Con...
CVE-2025-39497MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dokan Dokan Pro al...
CVE-2025-39484CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Waituk Entrada all...
CVE-2025-10933MEDIUM5.3An integer underflow vulnerability in the Silicon Labs Z-Wave Protocol Controller can lead to out of bounds memory reads...
CVE-2025-67315Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2025-67303HIGH7.5An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration a...
CVE-2025-65328MEDIUM6.5Mega-Fence (webgate-lib.*) 25.1.914 and prior trusts the first value of the X-Forwarded-For (XFF) header as the client I...
CVE-2025-14346CRITICAL9.8WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An...
CVE-2025-66376MEDIUM6.1Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sh...
CVE-2025-15029CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Mon...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now