2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-10951HIGH7.3A vulnerability was identified in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected by this vuln...
CVE-2025-10950MEDIUM6.3A vulnerability was determined in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected is the funct...
CVE-2025-10949LOW2.4A vulnerability was found in Changsha Developer Technology iView Editor up to 1.1.1. This impacts an unknown function of...
CVE-2025-10542CRITICAL9.8iMonitor EAM 9.6394 ships with default administrative credentials that are also displayed within the management client’s...
CVE-2025-10541HIGH7.8iMonitor EAM 9.6394 installs a system service (eamusbsrv64.exe) that runs with NT AUTHORITY\SYSTEM privileges. This serv...
CVE-2025-5494HIGH7.8ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This ...
CVE-2025-59839MEDIUM5.4The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for em...
CVE-2025-59834CRITICAL9.8ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0....
CVE-2025-59831HIGH8.8git-commiters is a Node.js function module providing committers stats for their git repository. Prior to version 0.1.2, ...
CVE-2025-59426MEDIUM4.3Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.130.1, the project's OIDC redirec...
CVE-2025-59422LOW3.1Dify is an open-source LLM app development platform. In version 1.8.1, a broken access control vulnerability on the /con...
CVE-2025-57317HIGH7.5apidoc-core is the core parser library to generate apidoc result following the apidoc-spec. A Prototype Pollution vulner...
CVE-2025-27261CRITICAL9.8Ericsson Indoor Connect 8855 contains an SQL injection vulnerability which if exploited can result in unauthorized discl...
CVE-2025-26278HIGH7.5A prototype pollution in the lib.set function of dref v0.1.2 allows attackers to cause a Denial of Service (DoS) via sup...
CVE-2025-10948HIGH8.8A vulnerability has been found in MikroTik RouterOS 7. This affects the function parse_json_element of the file /rest/ip...
CVE-2025-10540MEDIUM6.5iMonitor EAM 9.6394 transmits communication between the EAM client agent and the EAM server, as well as between the EAM ...
CVE-2025-10467HIGH8.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PROLIZ Comp...
CVE-2025-10947MEDIUM5.5A flaw has been found in Sistemas Pleno Gestão de Locação up to 2025.7.x. The impacted element is an unknown function of...
CVE-2025-10946MEDIUM5.1A vulnerability was detected in nuz007 smsboom up to 01b2f35bbbc23f3e0f60f38ca0e3d1b286f8d674. The affected element is a...
CVE-2025-10945MEDIUM5.1A security vulnerability has been detected in nuz007 smsboom up to 01b2f35bbbc23f3e0f60f38ca0e3d1b286f8d674. Impacted is...
CVE-2025-10944MEDIUM5.1A weakness has been identified in yi-ge get-header-ip up to 589b23d0eb0043c310a6a13ce4bbe2505d0d0b15. This issue affects...
CVE-2025-10449HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saysis Computer Systems ...
CVE-2025-40698HIGH8.7SQL injection vulnerability in Prevengos v2.44 by Nedatec Consulting. This vulnerability allows an attacker to retrieve,...
CVE-2025-10957HIGH8.7This vulnerability exists in the Syrotech SY-GPON-2010-WADONT router due to improper access control in its FTP service. ...
CVE-2025-10943MEDIUM5.1A security flaw has been discovered in MikeCen WeChat-Face-Recognition up to 6e3f72bf8547d80b59e330f1137e4aa505f492c1. T...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now