2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-57605HIGH8.8Lack of server-side authorisation on department admin assignment APIs in AiKaan IoT Platform allows authenticated users ...
CVE-2025-57430HIGH7.5Creacast Creabox Manager 4.4.4 exposes sensitive configuration data via a publicly accessible endpoint /get. When access...
CVE-2025-36202HIGH8.8IBM webMethods Integration 10.15 and 11.1 could allow an authenticated user with required execute Services to execute co...
CVE-2025-35041HIGH7.7Airship AI Acropolis allows unlimited MFA attempts for 15 minutes after a user has logged in with valid credentials. A r...
CVE-2025-10805HIGH8.8A vulnerability was determined in Campcodes Online Beauty Parlor Management System 1.0. This affects an unknown part of ...
CVE-2025-10804HIGH8.8A vulnerability was found in Campcodes Online Beauty Parlor Management System 1.0. Affected by this issue is some unknow...
CVE-2025-9038HIGH7.5Improper Privilege Management vulnerability in GE Vernova S1 Agile Configuration Software on Windows allows Privilege Es...
CVE-2025-10803HIGH8.8A vulnerability has been found in Tenda AC23 up to 16.03.07.52. Affected by this vulnerability is the function sscanf of...
CVE-2025-51006HIGH7.8Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the dlt_linuxsll2_cleanup() function i...
CVE-2025-10854HIGH8.1The txtai framework allows the loading of compressed tar files as embedding indices. While the validate function is inte...
CVE-2025-9983HIGH7.1GALAYOU G2 cameras stream video output via RTSP streams. By default these streams are protected by randomly generated cr...
CVE-2025-10792HIGH8.8A security vulnerability has been detected in D-Link DIR-513 A1FW110. Affected is an unknown function of the file /gofor...
CVE-2025-10009HIGH8.6Incorrect handling of uploaded files in the admin "Restore" function in Invoice Ninja <= 5.11.72 allows attackers with a...
CVE-2025-10790HIGH8.8A security flaw has been discovered in SourceCodester Simple Forum Discussion System 1.0. This affects an unknown functi...
CVE-2025-5962HIGH7.7A flaw was found in the Lightspeed history service. Insufficient access controls allow a local, unprivileged user to acc...
CVE-2025-10780HIGH8.8A vulnerability was determined in CodeAstro Simple Pharmacy Management 1.0. This affects an unknown function of the file...
CVE-2025-10775HIGH7.2A security vulnerability has been detected in Wavlink WL-NU516U1 240425. This vulnerability affects the function sub_401...
CVE-2025-10773HIGH8.8A security flaw has been discovered in B-Link BL-AC2100 up to 1.0.3. Affected by this issue is the function delshrpath o...
CVE-2025-53692HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sitecore Si...
CVE-2025-10765HIGH7.2A security flaw has been discovered in SeriaWei ZKEACMS up to 4.3. This vulnerability affects the function CheckPage/Sug...
CVE-2025-10764HIGH8.8A vulnerability was identified in SeriaWei ZKEACMS up to 4.3. This affects the function Edit of the file src/ZKEACMS.Eve...
CVE-2025-10757HIGH8.8A weakness has been identified in UTT 1200GW up to 3.0.0-170831. The affected element is an unknown function of the file...
CVE-2025-10756HIGH8.8A security flaw has been discovered in UTT HiPER 840G up to 3.1.1-190328. Impacted is an unknown function of the file /g...
CVE-2025-9079HIGH7.2Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to ...
CVE-2025-54815HIGH8.8Server-side template injection (SSTI) vulnerability in PPress 0.0.9 allows attackers to execute arbitrary code via craft...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now