2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-50983HIGH8.3SQL Injection vulnerability exists in the sortKey parameter of the GET /api/v1/wanted/cutoff API endpoint in readarr 0.4...
CVE-2025-53105HIGH7.5GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that...
CVE-2025-9532HIGH8.8A flaw has been found in Portabilis i-Educar up to 2.10. This impacts an unknown function of the file /RegraAvaliacao/vi...
CVE-2025-9531HIGH8.8A vulnerability was detected in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/a...
CVE-2025-9529HIGH7.2A weakness has been identified in Campcodes Payroll Management System 1.0. The affected element is the function include ...
CVE-2025-9528HIGH7.2A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the function systemCommand of th...
CVE-2025-9527HIGH8.8A vulnerability was found in Linksys E1700 1.0.0.4.003. This affects the function QoSSetup of the file /goform/QoSSetup....
CVE-2025-43882HIGH7.8Dell ThinOS 10, versions prior to 2508_10.0127, contains an Unverified Ownership vulnerability. A local low-privileged a...
CVE-2025-43730HIGH7.8Dell ThinOS 10, versions prior to 2508_10.0127, contains an Improper Neutralization of Argument Delimiters in a Command ...
CVE-2025-43729HIGH7.8Dell ThinOS 10, versions prior to 2508_10.0127, contains an Incorrect Permission Assignment for Critical Resource vulner...
CVE-2025-9526HIGH8.8A vulnerability has been found in Linksys E1700 1.0.0.4.003. Affected by this issue is the function setSysAdm of the fil...
CVE-2025-9525HIGH8.8A flaw has been found in Linksys E1700 1.0.0.4.003. Affected by this vulnerability is the function setWan of the file /g...
CVE-2025-30064HIGH8.8An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function chec...
CVE-2025-30038HIGH7.3The vulnerability consists of a session ID leak when saving a file downloaded from CGM CLININET. The identifier is expos...
CVE-2025-30037HIGH8.8The system exposes several endpoints, typically including "/int/" in their path, that should be restricted to internal s...
CVE-2025-30036HIGH8.8Stored XSS vulnerability exists in the "Oddział" (Ward) module, in the death diagnosis description field, and allows the...
CVE-2025-57846HIGH8.5Multiple i-フィルター products contain an issue with incorrect default permissions. If this vulnerability is exploited, a loc...
CVE-2025-57797HIGH8.5Incorrect privilege assignment vulnerability exists in ScanSnap Manager installers versions prior to V6.5L61. If this vu...
CVE-2025-57820HIGH7.9Svelte devalue is a utility library. Prior to version 5.3.2, a string passed to devalue.parse could represent an object ...
CVE-2025-35114HIGH8.7Agiloft Release 28 contains several accounts with default credentials that could allow local privilege escalation. The p...
CVE-2025-35113HIGH7.2Agiloft Release 28 does not properly neutralize special elements used in an EUI template engine, allowing an authenticat...
CVE-2025-22412HIGH8.8In multiple functions of sdp_server.cc, there is a possible use after free due to a logic error in the code. This could ...
CVE-2025-22411HIGH8.8In process_service_attr_rsp of sdp_discovery.cc, there is a possible use after free due to a logic error in the code. Th...
CVE-2025-22410HIGH8.4In multiple locations, there is a possible way to execute arbitrary code due to a use after free. This could lead to loc...
CVE-2025-22409HIGH8.4In rfc_send_buf_uih of rfc_ts_frames.cc, there is a possible way to execute arbitrary code due to a use after free. This...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now