2025 CVE Vulnerabilities

45,343 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-9595MEDIUM6.1A vulnerability was found in code-projects Student Information Management System 1.0. The impacted element is an unknown...
CVE-2025-58061MEDIUM5.5OpenEBS Local PV RawFile allows dynamic deployment of Stateful Persistent Node-Local Volumes & Filesystems for Kubernete...
CVE-2025-58058MEDIUM5.3xz is a pure golang package for reading and writing xz-compressed files. Prior to version 0.5.14, it is possible to put ...
CVE-2025-57220MEDIUM5.3An input validation flaw in the 'ate' service of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 to escalate privilege...
CVE-2025-57219MEDIUM5.3Incorrect access control in the endpoint /goform/ate of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 allows attacke...
CVE-2025-9195MEDIUM4.4Improper input validation in firmware of some Solidigm DC Products may allow an attacker with local access to cause a De...
CVE-2025-57218MEDIUM5.3Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the security_5g paramet...
CVE-2025-57217MEDIUM5.3Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the Password parameter ...
CVE-2025-31971MEDIUM5.1AIML Solutions for HCL SX is vulnerable to a URL validation vulnerability.  The issue may allow attackers to launch a se...
CVE-2025-57759MEDIUM4.3Contao is an Open Source CMS. In versions starting from 5.3.0 and prior to 5.3.38 and 5.6.1, under certain conditions, b...
CVE-2025-57758MEDIUM4.3Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, the table access voter in t...
CVE-2025-57757MEDIUM5.3Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, if a news feed contains pro...
CVE-2025-57756MEDIUM5.3Contao is an Open Source CMS. In versions starting from 4.9.14 and prior to 4.13.56, 5.3.38, and 5.6.1, protected conten...
CVE-2025-31979MEDIUM5.4A File Upload Validation Bypass vulnerability has been identified in the HCL BigFix SM, where the application fails to p...
CVE-2025-31977MEDIUM6.5HCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms.  An attacker with net...
CVE-2025-31972MEDIUM6.5HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS en...
CVE-2025-29364MEDIUM6.5spimsimulator spim v9.1.24 and before is vulnerable to Buffer Overflow in the READ_SYSCALL and WRITE_SYSCALL system call...
CVE-2025-25010MEDIUM6.5Incorrect authorization in Kibana can lead to privilege escalation via the built-in reporting_user role which incorrectl...
CVE-2025-56236MEDIUM6.1FormCms v0.5.5 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload feature. Authenticated us...
CVE-2025-54995MEDIUM6.5Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP...
CVE-2025-52054MEDIUM5.3An issue was discovered in Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router AC8v4.0 Firmware 16.03.33.05. The roo...
CVE-2025-51972MEDIUM6.5A SQL Injection vulnerability exists in the login.php of PuneethReddyHC Online Shopping System Advanced 1.0 due to impro...
CVE-2025-51971MEDIUM5.4A reflected Cross-Site Scripting (XSS) vulnerability exists in register.php of PuneethReddyHC Online Shopping System Adv...
CVE-2025-51969MEDIUM6.5A SQL Injection vulnerability exists in the product.php page of PuneethReddyHC Online Shopping System Advanced 1.0. This...
CVE-2025-51968MEDIUM6.5A SQL Injection vulnerability exists in the action.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now