2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-9866HIGH8.8Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to bypass c...
CVE-2025-9920HIGH7.2A security flaw has been discovered in Campcodes Recruitment Management System 1.0. This impacts the function include of...
CVE-2025-55852HIGH7.5Tenda AC8 v16.03.34.06 is vulnerable to Buffer Overflow in the formWifiBasicSet function via the parameter security or s...
CVE-2025-0280HIGH7.5A security vulnerability in HCL Compass can allow attacker to gain unauthorized database access.
CVE-2025-58644HIGH7.2Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes - TQL Edition ltl-freight-quotes...
CVE-2025-58643HIGH7.2Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes – Daylight Edition ltl-freight-q...
CVE-2025-58642HIGH7.2Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes – Day & Ross Edition ltl-freight...
CVE-2025-58637HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-58608HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-58604HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFunnels Mail Min...
CVE-2025-57151HIGH8.8phpgurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/userprofile.php via the ...
CVE-2025-57150HIGH7.2phpgurukul Complaint Management System in PHP 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/subcategory.php v...
CVE-2025-57147HIGH7.5A SQL Injection vulnerability was found in phpgurukul Complaint Management System 2.0. The vulnerability is due to lack ...
CVE-2025-57146HIGH8.1phpgurukul Complaint Management System in PHP 2.0 is vulnerable to SQL Injection in user/reset-password.php via the mobi...
CVE-2025-47421HIGH8.6Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in CRESTRON TOUCHSCREEN...
CVE-2025-2416HIGH8.6Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft LimonDesk allows Authentication Bypa...
CVE-2025-26210HIGH8.8DeepSeek R1 through V3.1 allows XSS, as demonstrated by JavaScript execution in the context of the run-html-chat.deepsee...
CVE-2025-53694HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), S...
CVE-2025-53691HIGH8.8Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) a...
CVE-2025-2415HIGH8.6Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft MyRezzta allows Authentication Bypas...
CVE-2025-9817HIGH7.5SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service
CVE-2025-21034HIGH7.8Out-of-bounds write in libsavsvc.so prior to SMR Sep-2025 Release 1 allows local attackers to potentially execute arbitr...
CVE-2025-9785HIGH7.7PaperCut Print Deploy is an optional component that integrates with PaperCut NG/MF which simplifies printer deployment a...
CVE-2025-58176HIGH8.8Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. In versions 0.9...
CVE-2025-9848HIGH7.5A security vulnerability has been detected in ScriptAndTools Real Estate Management System 1.0. The affected element is ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now