2025 CVE Vulnerabilities

45,179 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-12635MEDIUM5.4IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.12 are af...
CVE-2025-65228LOW3.5A stored cross-site scripting vulnerability exists in the web management interface of the R.V.R. Elettronica TLK302T tel...
CVE-2025-65230MEDIUM5.4Barix Instreamer v04.06 and v04.05 contains a stored cross-site scripting (XSS) vulnerability in the Web UI Configuratio...
CVE-2025-65229MEDIUM4.6A stored cross-site scripting (XSS) vulnerability exists in the web interface of Lyrion Music Server <= 9.0.3. An authen...
CVE-2025-65849CRITICAL9.1A cryptanalytic break in Altcha Proof-of-Work obfuscation mode version 0.8.0 and later allows for remote visitors to rec...
CVE-2025-65548CRITICAL9.1NUT-14 allows cashu tokens to be created with a preimage hash. However, nutshell (cashubtc/nuts) before 0.18.0 do not va...
CVE-2025-65271HIGH8.8Client-side template injection (CSTI) in Azuriom CMS admin dashboard allows a low-privilege user to execute arbitrary te...
CVE-2025-65231MEDIUM6.1Barix Instreamer v04.06 and earlier is vulnerable to Cross Site Scripting (XSS) in the Web UI I/O & Serial configuration...
CVE-2025-14261HIGH7.1The Litmus platform uses JWT for authentication and authorization, but the secret being used for signing the JWT is only...
CVE-2025-65804MEDIUM6.5Tenda AX3 v16.03.12.11 contains a stack overflow in formSetIptv via the iptvType parameter, which can cause memory corru...
CVE-2025-64081CRITICAL9.8SQL injection vulnerability in /php/api_patient_schedule.php in SourceCodester Patients Waiting Area Queue Management Sy...
CVE-2025-48625HIGH7In multiple locations of UsbDataAdvancedProtectionHook.java, there is a possible way to access USB data when the screen ...
CVE-2025-48608MEDIUM5.5In isValidMediaUri of SettingsProvider.java, there is a possible cross user media read due to a missing permission check...
CVE-2025-48606HIGH7.8In preparePackage of InstallPackageHelper.java, there is a possible way for an app to appear hidden upon installation wi...
CVE-2025-48569MEDIUM5.5In multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to lo...
CVE-2025-14259MEDIUM6.3A vulnerability was found in Jihai Jshop MiniProgram Mall System 2.9.0. Affected by this issue is some unknown functiona...
CVE-2025-14258CRITICAL9.8A vulnerability has been found in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unkno...
CVE-2025-65799MEDIUM4.3A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to e...
CVE-2025-65797MEDIUM6.5Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level priv...
CVE-2025-65795HIGH7.5Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create ...
CVE-2025-65363HIGH7.2Authenticated append-style command-injection Ruijie APs (AP_RGOS 11.1.x) allows an authenticated web user to execute app...
CVE-2025-63721HIGH8.8HummerRisk thru v1.5.0 is using a vulnerable Snakeyaml component, allowing attackers with normal user privileges to hit ...
CVE-2025-59391MEDIUM6.5A memory disclosure vulnerability exists in libcoap's OSCORE configuration parser in libcoap before release-4.3.5-patche...
CVE-2025-48639HIGH7.3In DefaultTransitionHandler.java, there is a possible way to unknowingly grant permissions to an app due to a tapjacking...
CVE-2025-48638HIGH7.8In __pkvm_load_tracing of trace.c, there is a possible out-of-bounds write due to improper input validation. This could ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now