2025 CVE Vulnerabilities

45,223 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-9902HIGH7.5Authorization Bypass Through User-Controlled Key vulnerability in AKIN Software Computer Import Export Industry and Trad...
CVE-2025-6919CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cats Information T...
CVE-2025-9337MEDIUM6.8A null pointer dereference has been identified in the AsIO3.sys driver. The vulnerability can be triggered by a speciall...
CVE-2025-9336MEDIUM6.8A stack buffer overflow has been identified in the AsIO3.sys driver. This vulnerability can be triggered by input manipu...
CVE-2025-11184MEDIUM6.9Cross-site scripting vulnerability in QGIS QWC2 Registration GUI <=v2025.03.31 allows an authorized attacker to plant ar...
CVE-2025-11183MEDIUM6.9Cross-Site Scripting vulnerability in attribute table in QGIS QWC2 <2025.08.14 allows an authorized attacker to plant ar...
CVE-2025-10720MEDIUM6.5The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However...
CVE-2025-9968HIGH8.5A link following vulnerability exists in the UnifyScanner component of Armoury Crate. This vulnerability may be triggere...
CVE-2025-9976CRITICAL9An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE ...
CVE-2025-11675HIGH8.6Enterprise Cloud Database developed by Ragic has an Arbitrary File Upload vulnerability, allowing privileged remote atta...
CVE-2025-11674MEDIUM6.9SOOP-CLM developed by PiExtract has a Server-Side Request Forgery vulnerability, allowing privileged remote attackers to...
CVE-2025-11673HIGH8.6SOOP-CLM developed by PiExtract has a Hidden Functionality vulnerability, allowing privileged remote attackers to exploi...
CVE-2025-11672MEDIUM6.9Uniweb/SoliPACS WebServer developed by EBM Technologies has a Missing Authentication vulnerability, allowing unauthentic...
CVE-2025-11671MEDIUM6.9Uniweb/SoliPACS WebServer developed by EBM Technologies has a Missing Authentication vulnerability, allowing unauthentic...
CVE-2025-11668HIGH7.2A vulnerability was determined in code-projects Automated Voting System 1.0. Affected by this issue is some unknown func...
CVE-2025-11667HIGH8.8A vulnerability was found in code-projects Automated Voting System 1.0. Affected by this vulnerability is an unknown fun...
CVE-2025-10558MEDIUM6.1A stored Cross-site Scripting (XSS) vulnerability affecting 3DSearch in 3DSwymer on Release 3DEXPERIENCE R2025x allows a...
CVE-2025-10557MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting Issue Management in ENOVIA Collaborative Industry Innovator ...
CVE-2025-10556MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting Specification Management in ENOVIA Specification Manager fro...
CVE-2025-10552MEDIUM6.1A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2025x allows an ...
CVE-2025-9265CRITICAL10A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker to deactivate user ver...
CVE-2025-8915HIGH8.7Hardcoded TLS private key and certificate in firmware in Kiloview N30 2.02.246 allows malicious adversary to do a Mann-i...
CVE-2025-27259MEDIUM5.4Ericsson Network Manager versions prior to ENM 25.2 GA contain a vulnerability that, if exploited, can exfiltrate limite...
CVE-2025-27258CRITICAL9.8Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an esc...
CVE-2025-11666HIGH7A flaw has been found in Tenda RP3 Pro up to 22.5.7.93. This impacts an unknown function of the file force_upgrade.sh of...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now