2025 CVE Vulnerabilities

45,181 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-66571CRITICAL9.3UNA CMS versions 9.0.0-RC1 - 14.0.0-RC4 contain a PHP object injection vulnerability in BxBaseMenuSetAclLevel.php where ...
CVE-2025-66555HIGH8.8AirKeyboard iOS App 1.0.5 contains a missing authentication vulnerability that allows unauthenticated attackers to type ...
CVE-2025-66479LOW1.8Anthropic Sandbox Runtime is a lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrar...
CVE-2025-66237HIGH8.4DCIM dcTrack platforms utilize default and hard-coded credentials for access. An attacker could use these credentials to...
CVE-2025-65959MEDIUM5.4Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a St...
CVE-2025-63896HIGH7.6An issue in the Bluetooth Human Interface Device (HID) of JXL 9 Inch Car Android Double Din Player Android v12.0 allows ...
CVE-2025-55948HIGH7.3This vulnerability fundamentally arises from yzcheng90 X-SpringBoot 6.0's implementation of role-based access control (R...
CVE-2025-27935HIGH8.6The OTP Integration Kit for PingFederate fails to enforce HTTP method validation and state validation properly. The serv...
CVE-2025-13543HIGH8.8The PostGallery plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in th...
CVE-2025-65958HIGH7.1Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a Se...
CVE-2025-65883HIGH8.4A vulnerability has been identified in Genexis Platinum P4410 router (Firmware P4410-V2–1.41) that allows a local networ...
CVE-2025-65806MEDIUM4.3The E-POINT CMS eagle.gsam-1169.1 file upload feature improperly handles nested archive files. An attacker can upload a ...
CVE-2025-63499MEDIUM6.1Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.
CVE-2025-29269CRITICAL9.8ALLNET ALL-RUT22GW v3.3.8 was discovered to contain an OS command injection vulnerability via the command parameter in t...
CVE-2025-29268CRITICAL9.8ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the libicos.so library.
CVE-2025-12997LOW3.1Insecure Direct Object Reference vulnerability in Medtronic CareLink Network which allows an authenticated attacker with...
CVE-2025-12996MEDIUM4.1Medtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext ...
CVE-2025-12995CRITICAL9.8Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint ...
CVE-2025-12994MEDIUM5.3Medtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an ...
CVE-2025-12097HIGH8.7There is a relative path traversal vulnerability in the NI System Web Server that may result in information disclosure. ...
CVE-2025-65945HIGH7.5auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth...
CVE-2025-65637HIGH7.5A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line pa...
CVE-2025-63362CRITICAL9.8Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.00...
CVE-2025-63361MEDIUM5.7Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.00...
CVE-2025-59788MEDIUM5.4Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions bef...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now