2025 CVE Vulnerabilities

45,155 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-52494HIGH7.5Adacore Ada Web Server (AWS) before 25.2 is vulnerable to a denial-of-service (DoS) condition due to improper handling o...
CVE-2025-45805HIGH7.6In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript cod...
CVE-2025-20336HIGH7.5A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and C...
CVE-2025-20326HIGH8.8A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and ...
CVE-2025-20287HIGH8.8A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow a...
CVE-2025-9959HIGH7.6Incomplete validation of dunder attributes allows an attacker to escape from the Local Python execution environment sand...
CVE-2025-9866HIGH8.8Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to bypass c...
CVE-2025-9920HIGH7.2A security flaw has been discovered in Campcodes Recruitment Management System 1.0. This impacts the function include of...
CVE-2025-55852HIGH7.5Tenda AC8 v16.03.34.06 is vulnerable to Buffer Overflow in the formWifiBasicSet function via the parameter security or s...
CVE-2025-0280HIGH7.5A security vulnerability in HCL Compass can allow attacker to gain unauthorized database access.
CVE-2025-58644HIGH7.2Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes - TQL Edition ltl-freight-quotes...
CVE-2025-58643HIGH7.2Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes – Daylight Edition ltl-freight-q...
CVE-2025-58642HIGH7.2Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes – Day & Ross Edition ltl-freight...
CVE-2025-58637HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-58608HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-58604HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFunnels Mail Min...
CVE-2025-57151HIGH8.8phpgurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/userprofile.php via the ...
CVE-2025-57150HIGH7.2phpgurukul Complaint Management System in PHP 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/subcategory.php v...
CVE-2025-57147HIGH7.5A SQL Injection vulnerability was found in phpgurukul Complaint Management System 2.0. The vulnerability is due to lack ...
CVE-2025-57146HIGH8.1phpgurukul Complaint Management System in PHP 2.0 is vulnerable to SQL Injection in user/reset-password.php via the mobi...
CVE-2025-47421HIGH8.6Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in CRESTRON TOUCHSCREEN...
CVE-2025-2416HIGH8.6Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft LimonDesk allows Authentication Bypa...
CVE-2025-26210HIGH8.8DeepSeek R1 through V3.1 allows XSS, as demonstrated by JavaScript execution in the context of the run-html-chat.deepsee...
CVE-2025-53694HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), S...
CVE-2025-53691HIGH8.8Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now