2025 CVE Vulnerabilities

45,227 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-59745HIGH7.5Vulnerability in the cryptographic algorithm of AndSoft's e-TMS v25.03, which uses MD5 to encrypt passwords. MD5 is a cr...
CVE-2025-59744HIGH7.5Path traversal vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to access files only withi...
CVE-2025-59743CRITICAL9.8SQL injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability could allow an attacker to retrieve, create, u...
CVE-2025-59742CRITICAL9.8SQL injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability could allow an attacker to retrieve, create, u...
CVE-2025-59741CRITICAL9.8Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe...
CVE-2025-57443MEDIUM5.1FrostWire 6.14.0-build-326 for macOS contains permissive entitlements (allow-dyld-environment-variables, disable-library...
CVE-2025-59740CRITICAL9.8Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe...
CVE-2025-59739CRITICAL9.8Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe...
CVE-2025-59738CRITICAL9.8Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe...
CVE-2025-59737CRITICAL9.8Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe...
CVE-2025-59736CRITICAL9.8Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe...
CVE-2025-59735CRITICAL9.8Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe...
CVE-2025-56381MEDIUM6.5ERPNEXT v15.67.0 was discovered to contain multiple SQL injection vulnerabilities in the /api/method/frappe.desk.reportv...
CVE-2025-56380MEDIUM6.5Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the fra...
CVE-2025-56379MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the blog post feature of ERPNEXT v15.67.0 allows attackers to execu...
CVE-2025-53881MEDIUM6.9A UNIX Symbolic Link (Symlink) Following vulnerability in logrotate config in the exim package allowed privilege escalat...
CVE-2025-41010MEDIUM5.1Incorrect Cross-Origin Resource Sharing (CORS) configuration in Hiberus Sintra. Cross-Origin Resource Sharing (CORS) all...
CVE-2025-22862MEDIUM6.7An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS 7.4.0 through 7.4.7, 7.2....
CVE-2025-11240HIGH7.2An open redirect vulnerability existed in KNIME Business Hub prior to version 1.16.0. An unauthenticated remote attacker...
CVE-2025-11239MEDIUM4.3Potentially sensitive information in jobs on KNIME Business Hub prior to 1.16.0 were visible to all members of the user'...
CVE-2025-0642MEDIUM6.3Use of Hard-coded Credentials, Authorization Bypass Through User-Controlled Key vulnerability in PosCube Hardware Softwa...
CVE-2025-41064CRITICAL9.3Incorrect authentication vulnerability in OpenSIAC, which could allow an attacker to impersonate a person using Cl@ve as...
CVE-2025-54293MEDIUM6.5Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attacker...
CVE-2025-40992MEDIUM5.1Stored XSS vulnerability in Creativeitem Sociopro due to lack of proper validation of user inputs via the endpoint '/soc...
CVE-2025-40991MEDIUM5.4Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now