2025 CVE Vulnerabilities

45,158 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-55422HIGH8.8In FoxCMS 1.2.6, there is a reflected Cross Site Scripting (XSS) vulnerability in /index.php/plus.
CVE-2025-51667HIGH7An issue was discovered in simple-admin-core v1.2.0 thru v1.6.7. The /sys-api/role/update interface in the simple-admin-...
CVE-2025-50979HIGH8.6NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The sear...
CVE-2025-34161HIGH8.8Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deplo...
CVE-2025-34159HIGH8.8Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application d...
CVE-2025-20344HIGH7.2A vulnerability in the backup restore functionality of Cisco Nexus Dashboard could allow an authenticated, remote attack...
CVE-2025-20317HIGH7.1A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controll...
CVE-2025-20241HIGH7.4A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) feature of Cisco NX-OS Software for Cisco Nexu...
CVE-2025-50983HIGH8.3SQL Injection vulnerability exists in the sortKey parameter of the GET /api/v1/wanted/cutoff API endpoint in readarr 0.4...
CVE-2025-53105HIGH7.5GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that...
CVE-2025-9532HIGH8.8A flaw has been found in Portabilis i-Educar up to 2.10. This impacts an unknown function of the file /RegraAvaliacao/vi...
CVE-2025-9531HIGH8.8A vulnerability was detected in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/a...
CVE-2025-9529HIGH7.2A weakness has been identified in Campcodes Payroll Management System 1.0. The affected element is the function include ...
CVE-2025-9528HIGH7.2A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the function systemCommand of th...
CVE-2025-9527HIGH8.8A vulnerability was found in Linksys E1700 1.0.0.4.003. This affects the function QoSSetup of the file /goform/QoSSetup....
CVE-2025-43882HIGH7.8Dell ThinOS 10, versions prior to 2508_10.0127, contains an Unverified Ownership vulnerability. A local low-privileged a...
CVE-2025-43730HIGH7.8Dell ThinOS 10, versions prior to 2508_10.0127, contains an Improper Neutralization of Argument Delimiters in a Command ...
CVE-2025-43729HIGH7.8Dell ThinOS 10, versions prior to 2508_10.0127, contains an Incorrect Permission Assignment for Critical Resource vulner...
CVE-2025-9526HIGH8.8A vulnerability has been found in Linksys E1700 1.0.0.4.003. Affected by this issue is the function setSysAdm of the fil...
CVE-2025-9525HIGH8.8A flaw has been found in Linksys E1700 1.0.0.4.003. Affected by this vulnerability is the function setWan of the file /g...
CVE-2025-30064HIGH8.8An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function chec...
CVE-2025-30038HIGH7.3The vulnerability consists of a session ID leak when saving a file downloaded from CGM CLININET. The identifier is expos...
CVE-2025-30037HIGH8.8The system exposes several endpoints, typically including "/int/" in their path, that should be restricted to internal s...
CVE-2025-30036HIGH8.8Stored XSS vulnerability exists in the "Oddział" (Ward) module, in the death diagnosis description field, and allows the...
CVE-2025-57846HIGH8.5Multiple i-フィルター products contain an issue with incorrect default permissions. If this vulnerability is exploited, a loc...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now