2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-34038HIGH7.5A SQL injection vulnerability exists in Weaver E-cology 8.0 via the getdata.jsp endpoint. The application directly passe...
CVE-2025-6535HIGH8.8A vulnerability has been found in xxyopen/201206030 novel-plus up to 5.1.3 and classified as critical. This vulnerabilit...
CVE-2025-34034HIGH8.8A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems. The app...
CVE-2025-34033HIGH8.8An OS command injection vulnerability exists in the Blue Angel Software Suite running on embedded Linux devices via the ...
CVE-2025-34031HIGH7.5A path traversal vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the query parameter in jsm...
CVE-2025-6529HIGH8.8A vulnerability was found in 70mai M300 up to 20250611 and classified as critical. Affected by this issue is some unknow...
CVE-2025-52558HIGH7changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification se...
CVE-2025-23092HIGH7.2Mitel OpenScape Accounting Management through V5 R1.1.0 could allow an authenticated attacker with administrative privil...
CVE-2025-48026HIGH7.5A vulnerability in the WebApl component of Mitel OpenScape Xpressions through V7R1 FR5 HF43 P913 could allow an unauthen...
CVE-2025-44528HIGH7.5An issue in Texas Instruments LP-CC2652RB SimpleLink CC13XX CC26XX SDK 7.41.00.17 allows attackers to cause a Denial of ...
CVE-2025-50349HIGH7.5PHPGurukul Pre-School Enrollment System Project V1.0 is vulnerable to Directory Traversal in update-teacher-pic.php.
CVE-2025-50348HIGH7.5PHPGurukul Pre-School Enrollment System Project V1.0 is vulnerable to Directory Traversal in update-class-pic.php.
CVE-2025-49144HIGH7.3Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerabilit...
CVE-2025-49126HIGH8.8Visionatrix is an AI Media processing tool using ComfyUI. In versions 1.5.0 to before 2.5.1, the /docs/flows endpoint is...
CVE-2025-6516HIGH7.8A vulnerability has been found in HDF5 up to 1.14.6 and classified as critical. This vulnerability affects the function ...
CVE-2025-6511HIGH8.8A vulnerability classified as critical has been found in Netgear EX6150 1.0.0.46_1.0.76. This affects the function sub_4...
CVE-2025-6510HIGH8.8A vulnerability was found in Netgear EX6100 1.0.2.28_1.1.138. It has been rated as critical. Affected by this issue is t...
CVE-2025-2171HIGH7.8Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attem...
CVE-2025-52922HIGH7.4Innoshop through 0.4.1 allows directory traversal via FileManager API endpoints. An authenticated attacker with access t...
CVE-2025-23049HIGH8.4Meridian Technique Materialise OrthoView through 7.5.1 allows OS Command Injection when servlet sharing is enabled.
CVE-2025-27387HIGH7.4OPPO Clone Phone uses a weak password WiFi hotspot to transfer files, resulting in Information disclosure.
CVE-2025-6487HIGH8.8A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been rated as critical. This issue affects the...
CVE-2025-6486HIGH8.8A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been declared as critical. This vulnerability ...
CVE-2025-6484HIGH7.2A vulnerability was found in code-projects Online Shopping Store 1.0 and classified as critical. Affected by this issue ...
CVE-2025-6422HIGH8.8A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. Affected by this...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now