2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-25589HIGH8.1An XML external entity (XXE) injection vulnerability in the component /weixin/aes/XMLParse.java of yimioa before v2024.0...
CVE-2025-30117HIGH7.3An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Managing Settings and Obtaining Sensitive Dat...
CVE-2025-30116HIGH7.5An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Remotely Dumping of Video Footage and the Liv...
CVE-2025-30111HIGH7.5On IROAD v9 devices, one can Remotely Dump Video Footage and the Live Video Stream. The dashcam exposes endpoints that a...
CVE-2025-30107HIGH7.5On IROAD V9 devices, Managing Settings and Obtaining Sensitive Data and Sabotaging the Car Battery can be performed by u...
CVE-2025-25585HIGH7.3Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorize...
CVE-2025-30106HIGH8.8On IROAD v9 devices, the dashcam has hardcoded default credentials ("qwertyuiop") that cannot be changed by the user. Th...
CVE-2025-2450HIGH8.8NI Vision Builder AI VBAI File Processing Missing Warning Remote Code Execution Vulnerability. This vulnerability allows...
CVE-2025-2449HIGH8.8NI FlexLogger usiReg URI File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows...
CVE-2025-25500HIGH7.5An issue in CosmWasm prior to v2.2.0 allows attackers to bypass capability restrictions in blockchains by exploiting a l...
CVE-2025-2493HIGH7.5Path Traversal vulnerability in Softdial Contact Center of Sytel Ltd. This vulnerability allows an attacker to manipulat...
CVE-2025-1468HIGH7.5An unauthenticated remote attacker can gain access to sensitive information including authentication information when us...
CVE-2025-25220HIGH8.8Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M ver...
CVE-2025-24306HIGH7.2Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M ver...
CVE-2025-0755HIGH7.5The various bson_append functions in the MongoDB C driver library may be susceptible to buffer overflow when performing ...
CVE-2025-2262HIGH7.3The The Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation plugin for WordPress is vu...
CVE-2025-2471HIGH8.8A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. Affected is an unkno...
CVE-2025-2419HIGH7.5A vulnerability classified as critical has been found in code-projects Real Estate Property Management System 1.0. Affec...
CVE-2025-2398HIGH8.6A vulnerability was found in China Mobile P22g-CIac, ZXWT-MIG-P4G4V, ZXWT-MIG-P8G8V, GT3200-4G4P and GT3200-8G8P up to 2...
CVE-2025-29910HIGH7.5CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL...
CVE-2025-2392HIGH7.2A vulnerability, which was classified as critical, has been found in code-projects Online Class and Exam Scheduling Syst...
CVE-2025-2389HIGH7.2A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. Affected by ...
CVE-2025-2388HIGH7.3A vulnerability was found in Keytop 路内停车收费系统 2.7.1. It has been declared as critical. Affected by this vulnerability is ...
CVE-2025-26125HIGH7.3An exposed ioctl in the IMFForceDelete driver of IObit Malware Fighter v12.1.0 allows attackers to arbitrarily delete fi...
CVE-2025-22473HIGH7.8Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now