2025 CVE Vulnerabilities

45,179 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-5610HIGH8.8A vulnerability, which was classified as critical, has been found in CodeAstro Real Estate Management System 1.0. Affect...
CVE-2025-48947HIGH7.7The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In Auth0 Next.js SDK ve...
CVE-2025-46341HIGH7.1FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, when the server is using HTTP auth via reverse p...
CVE-2025-5609HIGH8.8A vulnerability classified as critical was found in Tenda AC18 15.03.05.05. Affected by this vulnerability is the functi...
CVE-2025-5608HIGH8.8A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05. Affected is the function formsetreboott...
CVE-2025-5607HIGH8.8A vulnerability was found in Tenda AC18 15.03.05.05. It has been rated as critical. This issue affects the function form...
CVE-2025-31134HIGH7.5FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, an attacker can gain additional information abou...
CVE-2025-22243HIGH7.5VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation.
CVE-2025-5688HIGH7.5We have identified a buffer overflow issue allowing out-of-bounds write when processing LLMNR or mDNS queries with very ...
CVE-2025-20276HIGH7.2A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, remote attacker...
CVE-2025-20275HIGH7.8A vulnerability in the file opening process of Cisco Unified Contact Center Express (Unified CCX) Editor could allow an ...
CVE-2025-20261HIGH8.8A vulnerability in the SSH connection handling of Cisco Integrated Management Controller (IMC) for Cisco UCS B-Series, U...
CVE-2025-20163HIGH8.7A vulnerability in the SSH implementation of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticat...
CVE-2025-20130HIGH7.2A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) co...
CVE-2025-29093HIGH8.2File Upload vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbitrary cod...
CVE-2025-48961HIGH7.3Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protec...
CVE-2025-27811HIGH7.8A local privilege escalation in the razer_elevation_service.exe in Razer Synapse 4 through 4.0.86.2502180127 allows a lo...
CVE-2025-1701HIGH8.9CVE-2025-1701 is a high-severity vulnerability in the MIM Admin service. An attacker could exploit this vulnerability by...
CVE-2025-30415HIGH7.5Denial of service due to improper handling of malformed input. The following products are affected: Acronis Cyber Protec...
CVE-2025-5482HIGH8.8The Sunshine Photo Cart: Free Client Photo Galleries for Photographers plugin for WordPress is vulnerable to privilege e...
CVE-2025-47728HIGH7.3Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an att...
CVE-2025-47727HIGH7.3Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attack...
CVE-2025-47726HIGH7.3Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attack...
CVE-2025-47725HIGH7.3Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attack...
CVE-2025-47724HIGH7.3Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attack...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now