2025 CVE Vulnerabilities

45,224 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-43824MEDIUM5.4The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 ...
CVE-2025-59452MEDIUM5.8The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an...
CVE-2025-59451LOW3.5The YoSmart YoLink application through 2025-10-02 has session tokens with unexpectedly long lifetimes.
CVE-2025-59450MEDIUM4.3The YoSmart YoLink Smart Hub firmware 0382 is unencrypted, and data extracted from it can be used to determine network a...
CVE-2025-59449MEDIUM4.9The YoSmart YoLink MQTT broker through 2025-10-02 does not enforce sufficient authorization controls to prevent cross-ac...
CVE-2025-59448MEDIUM4.7Components of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet...
CVE-2025-59447LOW2.2The YoSmart YoLink Smart Hub device 0382 exposes a UART debug interface. An attacker with direct physical access can lev...
CVE-2025-11346CRITICAL9.8A vulnerability has been found in ILIAS up to 8.23/9.13/10.1. This affects the function unserialize of the component Bas...
CVE-2025-61985LOW3.6ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a Prox...
CVE-2025-61984LOW3.6ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources...
CVE-2025-11345CRITICAL9.8A flaw has been found in ILIAS up to 8.23/9.13/10.1. Affected by this issue is the function unserialize of the component...
CVE-2025-11344CRITICAL9.8A vulnerability was detected in ILIAS up to 8.23/9.13/10.1. Affected by this vulnerability is an unknown functionality o...
CVE-2025-6985HIGH7.5The HTMLSectionSplitter class in langchain-text-splitters version 0.3.8 is vulnerable to XML External Entity (XXE) attac...
CVE-2025-57515CRITICAL9.8A SQL injection vulnerability has been identified in Uniclare Student Portal v2. This flaw allows remote attackers to in...
CVE-2025-56382MEDIUM6.1A stored Cross-site scripting (XSS) vulnerability exists in the Customer Management Module of LionCoders SalePro POS 5.4...
CVE-2025-28129MEDIUM5.4Phpgurukul Hostel Management System 2.1 is vulnerable to clickjacking.
CVE-2025-11343HIGH8.6A security vulnerability has been detected in code-projects Student Crud Operation 3.3. Affected is an unknown function ...
CVE-2025-11342CRITICAL9.8A weakness has been identified in code-projects Online Course Registration 1.0. This impacts an unknown function of the ...
CVE-2025-61778CRITICAL9.3Akka.NET is a .NET port of the Akka project from the Scala / Java community. In all versions of Akka.Remote from v1.2.0 ...
CVE-2025-61777CRITICAL9.1Flag Forge is a Capture The Flag (CTF) platform. Starting in version 2.0.0 and prior to version 2.3.2, the `/api/admin/b...
CVE-2025-61769MEDIUM6.1Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including...
CVE-2025-61766MEDIUM6.5Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to version 1.0.0, infinite recu...
CVE-2025-60969MEDIUM5.7Directory Traversal vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 Ver 4.00...
CVE-2025-60967HIGH7.3Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 V...
CVE-2025-60965CRITICAL9.1OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.0...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now