2025 CVE Vulnerabilities

45,181 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14016HIGH8.1A security vulnerability has been detected in macrozheng mall-swarm up to 1.0.3. Affected is the function delete of the ...
CVE-2025-14015CRITICAL9.8A weakness has been identified in H3C Magic B0 up to 100R002. This impacts the function EditWlanMacList of the file /gof...
CVE-2025-14013MEDIUM4.8A vulnerability was identified in JIZHICMS up to 2.5.5. The impacted element is an unknown function of the file /index.p...
CVE-2025-13488MEDIUM5.1Due to a regression introduced in version 3.83.0, a security header is no longer applied to certain user-uploaded conten...
CVE-2025-9127MEDIUM5.5A vulnerability exists in PX Enterprise whereby sensitive information may be logged under specific conditions.
CVE-2025-63363HIGH7.5A lack of Management Frame Protection in Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V...
CVE-2025-14012HIGH7.2A vulnerability was determined in JIZHICMS up to 2.5.5. The affected element is the function deleteAll/findAll/delete of...
CVE-2025-14011HIGH7.2A vulnerability was found in JIZHICMS up to 2.5.5. Impacted is the function commentlist of the file /index.php/admins/Co...
CVE-2025-66516CRITICAL9.8Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules...
CVE-2025-66373MEDIUM4.8Akamai Ghost on Akamai CDN edge servers before 2025-11-17 has a chunked request body processing error that can result in...
CVE-2025-66287HIGH8.8A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper me...
CVE-2025-63364HIGH7.5Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.00...
CVE-2025-8074MEDIUM5.6Origin validation error vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.3-13973 allows local users...
CVE-2025-65516MEDIUM6.1A stored cross-site scripting (XSS) vulnerability was discovered in Seafile Community Edition prior to version 13.0.12. ...
CVE-2025-63681MEDIUM4.3open-webui v0.6.33 is vulnerable to Incorrect Access Control. The API /api/tasks/stop/ directly accesses and cancels tas...
CVE-2025-61148MEDIUM6.5An Insecure Direct Object Reference (IDOR) vulnerability in the EduplusCampus 3.0.1 Student Payment API allows authentic...
CVE-2025-57213HIGH7.5Incorrect access control in the component orderService.queryObject of platform v1.0.0 allows attackers to access sensiti...
CVE-2025-57212HIGH7.5Incorrect access control in the component ApiOrderService.java of platform v1.0.0 allows attackers to access sensitive i...
CVE-2025-57210HIGH7.5Incorrect access control in the component ApiPayController.java of platform v1.0.0 allows attackers to access sensitive ...
CVE-2025-56427HIGH7.5Directory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitive information via th...
CVE-2025-54160HIGH7.8Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology Bee...
CVE-2025-54159HIGH7.5Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attack...
CVE-2025-54158HIGH7.8Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-139...
CVE-2025-40266HIGH8.2In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Check the untrusted offset in FF-A memo...
CVE-2025-40265In the Linux kernel, the following vulnerability has been resolved: vfat: fix missing sb_min_blocksize() return value c...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now