2025 CVE Vulnerabilities

45,160 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-41451HIGH8.7Improper neutralization of alarm-to-mail configuration fields used in an OS shell Command ('Command Injection') in Danfo...
CVE-2025-51606HIGH8.8hippo4j 1.0.0 to 1.5.0, uses a hard-coded secret key in its JWT (JSON Web Token) creation. This allows attackers with ac...
CVE-2025-55231HIGH7.5Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an...
CVE-2025-55230HIGH7.8Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locall...
CVE-2025-54460HIGH7.1The vulnerability, if exploited, could allow an authenticated miscreant (with privileges to create or access publicatio...
CVE-2025-51989HIGH7HTML injection vulnerability in the registration interface in Evolution Consulting Kft. HRmaster module v235 allows an a...
CVE-2025-41415HIGH7.1The vulnerability, if exploited, could allow an authenticated miscreant (with privileges to access publication targets)...
CVE-2025-27721HIGH8.7Unauthorized users can access INFINITT PACS System Manager without proper authorization, which could lead to unauthoriz...
CVE-2025-57751HIGH7.7pyLoad is the free and open-source Download Manager written in pure Python. The jk parameter is received in pyLoad CNL B...
CVE-2025-38743HIGH7.8Dell iDRAC Service Module (iSM), versions prior to 6.0.3.0, contains a Buffer Access with Incorrect Length Value vulnera...
CVE-2025-7051HIGH8.3On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers ...
CVE-2025-55524HIGH7.3Insecure permissions in Agent-Zero v0.8.* allow attackers to arbitrarily reset the system via unspecified vectors.
CVE-2025-52351HIGH8.8Aikaan IoT management platform v3.25.0325-5-g2e9c59796 sends a newly generated password to users in plaintext via email ...
CVE-2025-9310HIGH7.5A vulnerability was determined in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3. Affected by this vuln...
CVE-2025-9309HIGH7A vulnerability was found in Tenda AC10 16.03.10.13. Affected is an unknown function of the file /etc_ro/shadow of the c...
CVE-2025-57765HIGH8.2WeGIA is a Web manager for charitable institutions. Prior to 3.4.7, a Reflected Cross-Site Scripting (XSS) vulnerability...
CVE-2025-57764HIGH8.2WeGIA is a Web manager for charitable institutions. Prior to 3.4.7, a Reflected Cross-Site Scripting (XSS) vulnerability...
CVE-2025-57761HIGH8.8WeGIA is a Web manager for charitable institutions. Prior to 3.4.10, there is a SQL Injection vulnerability in the /html...
CVE-2025-57755HIGH8.1claude-code-router is a powerful tool to route Claude Code requests to different models and customize any request. Due t...
CVE-2025-55743HIGH8.8UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, the i...
CVE-2025-55420HIGH8.8A Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6. When a crafted script is ...
CVE-2025-55383HIGH8.6Moss before v0.15 has a file upload vulnerability. The "upload" function configuration allows attackers to upload files ...
CVE-2025-55297HIGH8.8ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. The BluFi example bundled in ESP-IDF was vulner...
CVE-2025-52194HIGH7.5A buffer overflow vulnerability exists in libsndfile version 1.2.2 and potentially earlier versions when processing malf...
CVE-2025-48956HIGH7.5vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.10.1.1, a Denial of Ser...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now