2025 CVE Vulnerabilities

45,227 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-47211MEDIUM4.9A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker ...
CVE-2025-47210MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac...
CVE-2025-46819HIGH7.1Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user ...
CVE-2025-46818HIGH7.3Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user ...
CVE-2025-44014HIGH8.8An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user accoun...
CVE-2025-44012MEDIUM6.5An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re...
CVE-2025-44011MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac...
CVE-2025-44010MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac...
CVE-2025-44009MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac...
CVE-2025-44008MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac...
CVE-2025-61593HIGH8.8Cursor is a code editor built for programming with AI. In versions 1.7 and below, a vulnerability in the way Cursor CLI ...
CVE-2025-61592HIGH8.8Cursor is a code editor built for programming with AI. In versions 1.7 and below, automatic loading of project-specific ...
CVE-2025-52653MEDIUM5.4HCL MyXalytics product is affected by Cross Site Scripting vulnerability in the web application. This can allow the exec...
CVE-2025-46817HIGH8.8Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user ...
CVE-2025-44007MEDIUM6.5An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re...
CVE-2025-44006MEDIUM6.5An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re...
CVE-2025-33040MEDIUM6.5An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re...
CVE-2025-33039MEDIUM6.5An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re...
CVE-2025-33034MEDIUM6.5A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the...
CVE-2025-61591HIGH8.8Cursor is a code editor built for programming with AI. In versions 1.7 and below, when MCP uses OAuth authentication wit...
CVE-2025-61590HIGH7.5Cursor is a code editor built for programming with AI. Versions 1.6 and below are vulnerable to Remote Code Execution (R...
CVE-2025-56551HIGH8.2An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate lo...
CVE-2025-60787HIGH7.2MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name...
CVE-2025-57423MEDIUM6.5A SQL injection vulnerability was discovered in the /articles endpoint of MyClub 0.5, affecting the query parameters Con...
CVE-2025-55972HIGH7.5A TCL Smart TV running a vulnerable UPnP/DLNA MediaRenderer implementation is affected by a remote, unauthenticated Deni...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now