2025 CVE Vulnerabilities

45,187 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13084HIGH7.6The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys. ...
CVE-2025-11461HIGH8.8Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user-controlled parameters int...
CVE-2025-65239MEDIUM4.3Incorrect access control in the /aux1/ocussd/trace endpoint of OpenCode Systems USSD Gateway OC Release:5, version 6.13....
CVE-2025-65238MEDIUM6.5Incorrect access control in the getSubUsersByProvider function of OpenCode Systems USSD Gateway OC Release: 5 Version 6....
CVE-2025-65237MEDIUM6.1A reflected cross-site scripted (XSS) vulnerability in OpenCode Systems USSD Gateway OC Release: 5 allows attackers to e...
CVE-2025-65236CRITICAL9.8OpenCode Systems USSD Gateway OC Release: 5 was discovered to contain a SQL injection vulnerability via the Session ID p...
CVE-2025-65235CRITICAL9.8OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 was discovered to contain a SQL injection vulnerability via ...
CVE-2025-63938MEDIUM6.5Tinyproxy through 1.11.2 contains an integer overflow vulnerability in the strip_return_port() function within src/reqs....
CVE-2025-46175HIGH7.5Ruoyi v4.8.0 is vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the au...
CVE-2025-62354CRITICAL9.8Improper neutralization of special elements used in an OS command ('command injection') in Cursor allows an unauthorized...
CVE-2025-56396HIGH8.8An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department havi...
CVE-2025-50402CRITICAL9.8FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter string fac...
CVE-2025-50399CRITICAL9.8FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter password.
CVE-2025-46174HIGH7.5Ruoyi v4.8.0 vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the reset...
CVE-2025-45311HIGH8.8Insecure permissions in fail2ban-client v0.11.2 allows attackers with limited sudo privileges to perform arbitrary opera...
CVE-2025-3747Rejected reason: This CVE ID was duplicated of CVE-2025-32801
CVE-2025-13601HIGH7.7A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_u...
CVE-2025-9191MEDIUM6.3The Houzez theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.6 via des...
CVE-2025-9163MEDIUM6.1The Houzez theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, ...
CVE-2025-13674MEDIUM5.5BPv7 dissector crash in Wireshark 4.6.0 allows denial of service
CVE-2025-62728MEDIUM5.4SQL injection vulnerability in Hive Metastore Server (HMS) when processing delete column statistics requests via the Thr...
CVE-2025-59390CRITICAL9.8Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSign...
CVE-2025-13735HIGH7.4Out-of-bounds Read vulnerability in ASR1903、ASR3901 in ASR Lapwing_Linux on Linux (nr_fw modules). This vulnerability is...
CVE-2025-9558HIGH7.6There is a potential OOB Write vulnerability in the gen_prov_start function in pb_adv.c. The full length of the received...
CVE-2025-9557HIGH7.6‭An out-of-bound write can lead to an arbitrary code execution. Even on devices with some form of memory protection, thi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now