2025 CVE Vulnerabilities

45,343 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-7735HIGH8.7The Hospital Information System developed by UNIMAX has a SQL Injection vulnerability, allowing unauthenticated remote a...
CVE-2025-34130HIGH8.7An unauthenticated arbitrary file read exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2....
CVE-2025-34129HIGH8.7A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_...
CVE-2025-34128HIGH8.6A buffer overflow vulnerability exists in the X360 VideoPlayer ActiveX control (VideoPlayer.ocx) version 2.6 when handli...
CVE-2025-34126HIGH8.7A path traversal vulnerability exists in RIPS Scanner version 0.54. The vulnerability allows remote attackers to read ar...
CVE-2025-34124HIGH8.4A buffer overflow vulnerability exists in Heroes of Might and Magic III Complete 4.0.0.0, HD Mod 3.808 build 9, and Demo...
CVE-2025-34123HIGH8.4A stack-based buffer overflow vulnerability exists in VideoCharge Studio 2.12.3.685 when processing a specially crafted ...
CVE-2025-34120HIGH8.7An unauthenticated file download vulnerability exists in LimeSurvey versions from 2.0+ up to and including 2.06+ Build 1...
CVE-2025-34119HIGH8.8A remote file disclosure vulnerability exists in EasyCafe Server 2.2.14, exploitable by unauthenticated remote attackers...
CVE-2025-34118HIGH8.7A path traversal vulnerability exists in Linknat VOS Manager versions prior to 2.1.9.07, including VOS2009 and early VOS...
CVE-2025-53908HIGH8.3RomM is a self-hosted rom manager and player. Versions prior to 3.10.3 and 4.0.0-beta.3 have an authenticated path trave...
CVE-2025-40777HIGH7.5If a `named` caching resolver is configured with `serve-stale-enable` `yes`, and with `stale-answer-client-timeout` set ...
CVE-2025-36097HIGH7.5IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 are vulnerable t...
CVE-2025-20284HIGH7.2A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execut...
CVE-2025-20283HIGH7.2A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execut...
CVE-2025-20274HIGH8.8A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated,...
CVE-2025-7357HIGH8.7LITEON IC48A firmware versions prior to 01.00.19r and LITEON IC80A firmware versions prior to 01.01.12e store FTP-server...
CVE-2025-53943HIGH8.7VoidBot Open-Source is a customizable Discord bot. VoidBot Open-Source versions 0.0.1 through 0.8.1 contain a vulnerabil...
CVE-2025-53938HIGH7.5WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. An Authenticati...
CVE-2025-5994HIGH8.7A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in caching resolvers that sup...
CVE-2025-37104HIGH7.1A security vulnerability has been identified in HPE Telco Service Orchestrator software. The vulnerability could allow a...
CVE-2025-32874HIGH7.5An issue was discovered in Kaseya Rapid Fire Tools Network Detective through 2.0.16.0. A vulnerability exists in the Enc...
CVE-2025-32353HIGH8.2Kaseya Rapid Fire Tools Network Detective 2.0.16.0 has Unencrypted Credentials (for privileged access) stored in the col...
CVE-2025-40776HIGH8.6A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-pois...
CVE-2025-40923HIGH7.3Plack-Middleware-Session before version 0.35 for Perl generates session ids insecurely. The default session id generato...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now