2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-67074MEDIUM6.5A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remot...
CVE-2025-67073CRITICAL9.8A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remot...
CVE-2025-66646HIGH7.5RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) ...
CVE-2025-66397HIGH8.3ChurchCRM is an open-source church management system. Prior to version 6.5.3, the allowRegistration, acceptKiosk, reload...
CVE-2025-66396HIGH7.2ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in th...
CVE-2025-65233MEDIUM6.1Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF' ...
CVE-2025-34442HIGH7.5AVideo versions prior to 20.1 disclose absolute filesystem paths via multiple public API endpoints. Returned metadata in...
CVE-2025-34441HIGH7.5AVideo versions prior to 20.1 expose sensitive user information through an unauthenticated public API endpoint. Response...
CVE-2025-34440MEDIUM6.1AVideo versions prior to 20.1 contain an open redirect vulnerability caused by insufficient validation of the siteRedire...
CVE-2025-34439MEDIUM6.1AVideo versions prior to 20.1 are vulnerable to an open redirect flaw due to missing validation of the cancelUri paramet...
CVE-2025-34438HIGH8.1AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permi...
CVE-2025-34437HIGH8.8AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned by other users. The...
CVE-2025-34436HIGH8.8AVideo versions prior to 20.1 allow any authenticated user to upload files into directories belonging to other users due...
CVE-2025-34435MEDIUM6.5AVideo versions prior to 20.1 are vulnerable to an insecure direct object reference (IDOR) that allows any authenticated...
CVE-2025-34434CRITICAL9.1AVideo versions prior to 20.1 with the ImageGallery plugin enabled is vulnerable to unauthenticated file upload and dele...
CVE-2025-14760MEDIUM6Missing cryptographic key commitment in the AWS SDK for C++ may allow a user with write access to the S3 bucket to intro...
CVE-2025-14759MEDIUM6Missing cryptographic key commitment in the Amazon S3 Encryption Client for .NET may allow a user with write access to t...
CVE-2025-67174HIGH7.5A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a ...
CVE-2025-67173MEDIUM6.8A Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrar...
CVE-2025-67171HIGH7.5Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via d...
CVE-2025-67170MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the...
CVE-2025-67168MEDIUM5.3RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords.
CVE-2025-66953HIGH8.8CSRF vulnerability in narda miteq Uplink Power Contril Unit UPC2 v.1.17 allows a remote attacker to execute arbitrary co...
CVE-2025-66395HIGH8.8ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in th...
CVE-2025-62521CRITICAL9.8ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code executio...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now