2025 CVE Vulnerabilities

45,334 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-7051HIGH8.3On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers ...
CVE-2025-55524HIGH7.3Insecure permissions in Agent-Zero v0.8.* allow attackers to arbitrarily reset the system via unspecified vectors.
CVE-2025-52351HIGH8.8Aikaan IoT management platform v3.25.0325-5-g2e9c59796 sends a newly generated password to users in plaintext via email ...
CVE-2025-9310HIGH7.5A vulnerability was determined in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3. Affected by this vuln...
CVE-2025-9309HIGH7A vulnerability was found in Tenda AC10 16.03.10.13. Affected is an unknown function of the file /etc_ro/shadow of the c...
CVE-2025-57765HIGH8.2WeGIA is a Web manager for charitable institutions. Prior to 3.4.7, a Reflected Cross-Site Scripting (XSS) vulnerability...
CVE-2025-57764HIGH8.2WeGIA is a Web manager for charitable institutions. Prior to 3.4.7, a Reflected Cross-Site Scripting (XSS) vulnerability...
CVE-2025-57761HIGH8.8WeGIA is a Web manager for charitable institutions. Prior to 3.4.10, there is a SQL Injection vulnerability in the /html...
CVE-2025-57755HIGH8.1claude-code-router is a powerful tool to route Claude Code requests to different models and customize any request. Due t...
CVE-2025-55743HIGH8.8UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, the i...
CVE-2025-55420HIGH8.8A Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6. When a crafted script is ...
CVE-2025-55383HIGH8.6Moss before v0.15 has a file upload vulnerability. The "upload" function configuration allows attackers to upload files ...
CVE-2025-55297HIGH8.8ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. The BluFi example bundled in ESP-IDF was vulner...
CVE-2025-52194HIGH7.5A buffer overflow vulnerability exists in libsndfile version 1.2.2 and potentially earlier versions when processing malf...
CVE-2025-48956HIGH7.5vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.10.1.1, a Denial of Ser...
CVE-2025-55564HIGH7.5Tenda AC15 v15.03.05.19_multi_TD01 has a stack overflow via the list parameter in the fromSetIpMacBind function.
CVE-2025-55370HIGH8.8Incorrect access control in the component \controller\ResourceController.java of jshERP v3.5 allows unauthorized attacke...
CVE-2025-55368HIGH8.8Incorrect access control in the component \controller\RoleController.java of jshERP v3.5 allows unauthorized attackers t...
CVE-2025-34158HIGH8.5Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spher...
CVE-2025-9300HIGH7.8A vulnerability was found in saitoha libsixel up to 1.10.3. Affected by this issue is the function sixel_debug_print_pal...
CVE-2025-9297HIGH8.8A vulnerability was detected in Tenda i22 1.0.0.3(4687). This impacts the function formWeixinAuthInfoGet of the file /go...
CVE-2025-8592HIGH8.1The Inspiro theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.2....
CVE-2025-48978HIGH7.5An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.11.0 and earlier) could allow a Command Injection by a mal...
CVE-2025-27216HIGH8.8Multiple Incorrect Permission Assignment for Critical Resource in UISP Application may allow a malicious actor with cert...
CVE-2025-27215HIGH8.1An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect Display Cast ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now