2025 CVE Vulnerabilities

45,213 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-26782HIGH7.5An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 210...
CVE-2025-26781HIGH7.5An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 210...
CVE-2025-10678CRITICAL9.3NetBird VPN when installed using vendor's provided script failed to remove or change default password of an admin accoun...
CVE-2025-8884MEDIUM5.5Authorization Bypass Through User-Controlled Key vulnerability in VHS Electronic Software Ltd. Co. ACE Center allows Pri...
CVE-2025-61456MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the index endpoin...
CVE-2025-61417HIGH8.8Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Att...
CVE-2025-57738HIGH7.2Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide cus...
CVE-2025-54957CRITICAL9.8An issue was discovered in Dolby UDC 4.5 through 4.13. A crash of the DD+ decoder process can occur when a malformed DD+...
CVE-2025-41390HIGH7.8An arbitrary code execution vulnerability exists in the git functionality of Truffle Security Co. TruffleHog 3.90.2. A s...
CVE-2025-61455CRITICAL9.8SQL Injection vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the signup.inc.php endpoint. The...
CVE-2025-11680MEDIUM5.9Out-of-bounds Write in unfilter_scanline in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during ...
CVE-2025-11679MEDIUM5.9Out-of-bounds Read in lws_upng_emit_next_line in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled du...
CVE-2025-11678HIGH7.5Stack-based Buffer Overflow in lws_adns_parse_label in warmcat libwebsockets allows, when the LWS_WITH_SYS_ASYNC_DNS fla...
CVE-2025-11677MEDIUM6.3Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker...
CVE-2025-61454MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the search endpoi...
CVE-2025-56224HIGH8.1A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 allows attackers to by...
CVE-2025-56223HIGH7.5A lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows attackers to cause a Den...
CVE-2025-56219HIGH7.1Incorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limitin...
CVE-2025-8349MEDIUM5.3Cross-site Scripting (XSS) stored vulnerability in Tawk Live Chat. This vulnerability allows an attacker to execute Java...
CVE-2025-57837LOW2.9Tileservice module is affected by information leak vulnerability, successful exploitation of this vulnerability may affe...
CVE-2025-41028CRITICAL9.3A SQL Injection vulnerability has been found in Epsilon RH by Grupo Castilla. This vulnerability allows an attacker to r...
CVE-2025-61932CRITICAL9.8Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of...
CVE-2025-57839MEDIUM4Photo module is affected by information leak vulnerability, successful exploitation of this vulnerability may affect ser...
CVE-2025-57838MEDIUM4Some Honor products are affected by information leak vulnerability, successful exploitation of this vulnerability may af...
CVE-2025-31342CRITICAL9.3An unrestricted upload of file with dangerous type vulnerability in the upload file function of Galaxy Software Services...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now