2025 CVE Vulnerabilities

45,209 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-56801MEDIUM5.1The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB ...
CVE-2025-56800MEDIUM5.1Reolink desktop application 8.18.12 contains a vulnerability in its local authentication mechanism. The application impl...
CVE-2025-56799MEDIUM6.5Reolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism...
CVE-2025-8050MEDIUM6.5External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal.  The vulnerability could...
CVE-2025-60790MEDIUM6.5ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is ...
CVE-2025-60507HIGH8.9Cross site scripting vulnerability in Moodle GeniAI plugin (local_geniai) 2.3.6. An authenticated user with Teacher role...
CVE-2025-60427MEDIUM6.5LibreTime 3.0.0-alpha.10 and possibly earlier is vulnerable to Broken Access Control, where a user with the DJ role can ...
CVE-2025-12031MEDIUM5.3HTTP Security Misconfiguration - Lacking Secure and HTTPOnly Attribute may allow reading the sensitive cookies from the ...
CVE-2025-11757HIGH8.7The CloudEdge Cloud does not sanitize the MQTT topic input, which could allow an attacker to leverage the MQTT wildcard ...
CVE-2025-62763MEDIUM5Zimbra Collaboration (ZCS) before 10.1.12 allows SSRF because of the configuration of the chat proxy.
CVE-2025-62605MEDIUM4.3Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon version 4.4, support for verifia...
CVE-2025-62598MEDIUM6.1WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to version 3.5.1, ...
CVE-2025-62597MEDIUM6.1WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to version 3.5.1, ...
CVE-2025-62595MEDIUM6.1Koa is expressive middleware for Node.js using ES2017 async functions. In versions 2.16.2 to before 2.16.3 and 3.0.1 to ...
CVE-2025-62518HIGH8.1astral-tokio-tar is a tar archive reading/writing library for async Rust. Versions of astral-tokio-tar prior to 0.5.6 co...
CVE-2025-60772CRITICAL9.8Improper authentication in the web-based management interface of NETLINK HG322G V1.0.00-231017, allows a remote unauthen...
CVE-2025-60511MEDIUM4.3Moodle OpenAI Chat Block plugin 3.0.1 (2025021700) suffers from an Insecure Direct Object Reference (IDOR) vulnerability...
CVE-2025-60506MEDIUM5.4Moodle PDF Annotator plugin v1.5 release 9 allows stored cross-site scripting (XSS) via the Public Comments feature. An ...
CVE-2025-60500HIGH7.2QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass...
CVE-2025-11534CRITICAL9.3The affected Raisecom devices allow SSH sessions to be established without completing user authentication. This could al...
CVE-2025-62250MEDIUM6.5Improper Authentication in Liferay Portal 7.4.0 through 7.4.3.132, and older unsupported versions, and Liferay DXP 2023....
CVE-2025-61220HIGH7.5The incomplete verification mechanism in the AutoBizLine com.mysecondline.app 1.2.91 allows attackers to log in as other...
CVE-2025-61194MEDIUM6.5daicuocms V1.3.13 contains a SQL injection vulnerability in the file library\think\db\Builder.php.
CVE-2025-61181MEDIUM6.5daicuocms V1.3.13 contains an arbitrary file upload vulnerability in the image upload feature.
CVE-2025-60751HIGH7.5GeographicLib 2.5 is vulnerable to Buffer Overflow in GeoConvert DMS::InternalDecode.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now