2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-9602MEDIUM6.5A vulnerability was found in Xinhu RockOA up to 2.6.9. Impacted is the function publicsaveAjax of the file /index.php. P...
CVE-2025-54142MEDIUM4Akamai Ghost before 2025-07-21 allows HTTP Request Smuggling via an OPTIONS request that has an entity body, because the...
CVE-2025-43284MEDIUM5.5An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6, macOS Sono...
CVE-2025-9595MEDIUM6.1A vulnerability was found in code-projects Student Information Management System 1.0. The impacted element is an unknown...
CVE-2025-58061MEDIUM5.5OpenEBS Local PV RawFile allows dynamic deployment of Stateful Persistent Node-Local Volumes & Filesystems for Kubernete...
CVE-2025-58058MEDIUM5.3xz is a pure golang package for reading and writing xz-compressed files. Prior to version 0.5.14, it is possible to put ...
CVE-2025-57220MEDIUM5.3An input validation flaw in the 'ate' service of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 to escalate privilege...
CVE-2025-57219MEDIUM5.3Incorrect access control in the endpoint /goform/ate of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 allows attacke...
CVE-2025-9195MEDIUM4.4Improper input validation in firmware of some Solidigm DC Products may allow an attacker with local access to cause a De...
CVE-2025-57218MEDIUM5.3Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the security_5g paramet...
CVE-2025-57217MEDIUM5.3Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the Password parameter ...
CVE-2025-31971MEDIUM5.1AIML Solutions for HCL SX is vulnerable to a URL validation vulnerability.  The issue may allow attackers to launch a se...
CVE-2025-57759MEDIUM4.3Contao is an Open Source CMS. In versions starting from 5.3.0 and prior to 5.3.38 and 5.6.1, under certain conditions, b...
CVE-2025-57758MEDIUM4.3Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, the table access voter in t...
CVE-2025-57757MEDIUM5.3Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, if a news feed contains pro...
CVE-2025-57756MEDIUM5.3Contao is an Open Source CMS. In versions starting from 4.9.14 and prior to 4.13.56, 5.3.38, and 5.6.1, protected conten...
CVE-2025-31979MEDIUM5.4A File Upload Validation Bypass vulnerability has been identified in the HCL BigFix SM, where the application fails to p...
CVE-2025-31977MEDIUM6.5HCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms.  An attacker with net...
CVE-2025-31972MEDIUM6.5HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS en...
CVE-2025-29364MEDIUM6.5spimsimulator spim v9.1.24 and before is vulnerable to Buffer Overflow in the READ_SYSCALL and WRITE_SYSCALL system call...
CVE-2025-25010MEDIUM6.5Incorrect authorization in Kibana can lead to privilege escalation via the built-in reporting_user role which incorrectl...
CVE-2025-56236MEDIUM6.1FormCms v0.5.5 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload feature. Authenticated us...
CVE-2025-54995MEDIUM6.5Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP...
CVE-2025-52054MEDIUM5.3An issue was discovered in Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router AC8v4.0 Firmware 16.03.33.05. The roo...
CVE-2025-51972MEDIUM6.5A SQL Injection vulnerability exists in the login.php of PuneethReddyHC Online Shopping System Advanced 1.0 due to impro...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now