2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-41077HIGH8.1IDOR vulnerability has been found in Viafirma Inbox v4.5.13 that allows any authenticated user without privileges in the...
CVE-2025-41005HIGH8.7Imaster's MEMS Events CRM contains an SQL injection vulnerability in‘keyword’ parameter in ‘/memsdemo/exchange_offers.ph...
CVE-2025-41004HIGH8.7Imaster's Patient Records Management System is vulnerable to SQL Injection in the endpoint ‘/projects/hospital/admin/com...
CVE-2025-14279HIGH8.1MLFlow versions up to and including 3.4.0 are vulnerable to DNS rebinding attacks due to a lack of Origin header validat...
CVE-2025-69276HIGH8.8Deserialization of Untrusted Data vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Object Injection...
CVE-2025-69274HIGH8.8Authorization Bypass Through User-Controlled Key vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows P...
CVE-2025-69273HIGH7.5Improper Authentication vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Authentication Bypass.This...
CVE-2025-69272HIGH7.5Cleartext Transmission of Sensitive Information vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sn...
CVE-2025-69271HIGH7.5Insufficiently Protected Credentials vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Atta...
CVE-2025-68493HIGH8.1Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 befo...
CVE-2025-62235HIGH8.1Authentication Bypass by Spoofing vulnerability in Apache NimBLE. Receiving specially crafted Security Request could le...
CVE-2025-53477HIGH7.5NULL Pointer Dereference vulnerability in Apache Nimble. Missing validation of HCI connection complete or HCI command T...
CVE-2025-52435HIGH7.5J2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE. Improper handling of Pause ...
CVE-2025-13457HIGH7.5The WooCommerce Square plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and...
CVE-2025-59057HIGH7.6React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 ...
CVE-2025-67070HIGH8.2A vulnerability exists in Intelbras CFTV IP NVD 9032 R Ftd V2.800.00IB00C.0.T, which allows an unauthenticated attacker ...
CVE-2025-66744HIGH7.5In Yonyou YonBIP v3 and before, the LoginWithV8 interface in the series data application service system is vulnerable to...
CVE-2025-46645HIGH7.2Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4....
CVE-2025-15495HIGH7.2A vulnerability was found in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admin/editsite...
CVE-2025-15494HIGH8.8A vulnerability has been found in RainyGao DocSys up to 2.02.37. This affects an unknown function of the file com/DocSys...
CVE-2025-15035HIGH7.3Improper Input Validation vulnerability in TP-Link Archer AXE75 v1.6 (vpn modules) allows an authenticated adjacent atta...
CVE-2025-67133HIGH7.5An issue in Hero Motocorp Vida V1 Pro 2.0.7 allows a local attacker to cause a denial of service via the BLE component
CVE-2025-56225HIGH7.5fluidsynth-2.4.6 and earlier versions is vulnerable to Null pointer dereference in fluid_synth_monopoly.c, that can be t...
CVE-2025-15492HIGH8.8A vulnerability was detected in RainyGao DocSys up to 2.02.36. The affected element is an unknown function of the file s...
CVE-2025-66052HIGH7.2Vivotek IP7137 camera with firmware version 0200a is vulnerable to command injection. Parameter "system_ntpIt" used by "...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now