2025 CVE Vulnerabilities

45,233 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-52367MEDIUM5.4Cross Site Scripting vulnerability in PivotX CMS v.3.0.0 RC 3 allows a remote attacker to execute arbitrary code via the...
CVE-2025-36064MEDIUM5.9IBM Sterling Connect:Express for Microsoft Windows 3.1.0.0 through 3.1.0.22 uses an inadequate account lockout setting t...
CVE-2025-10811CRITICAL9.8A flaw has been found in code-projects Hostel Management System 1.0. This affects an unknown function of the file /justi...
CVE-2025-10810CRITICAL9.8A vulnerability was detected in Campcodes Online Learning Management System 1.0. The impacted element is an unknown func...
CVE-2025-59420HIGH7.5Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.4, Authlib’s JWS verific...
CVE-2025-59418MEDIUM5.5BunnyPad is a note taking software. Prior to version 11.0.27000.0915, opening files greater than or equal to 20MB causes...
CVE-2025-57441CRITICAL9.8The Blackmagic ATEM Mini Pro 2.7 exposes sensitive device and stream configuration information via an unauthenticated Te...
CVE-2025-57440HIGH7.5The Blackmagic ATEM Mini Pro 2.7 exposes an undocumented Telnet service on TCP port 9993, which accepts unauthenticated ...
CVE-2025-57439HIGH8.8Creacast Creabox Manager 4.4.4 contains a critical Remote Code Execution vulnerability accessible via the edit.php endpo...
CVE-2025-57438MEDIUM6.8The 2wcom IP-4c 2.15.5 device suffers from a Broken Access Control vulnerability. Certain sensitive endpoints are intend...
CVE-2025-57437CRITICAL9.8The Blackmagic Web Presenter HD firmware version 3.3 exposes sensitive information via an unauthenticated Telnet service...
CVE-2025-55888HIGH7.3Cross-Site Scripting (XSS) vulnerability was discovered in the Ajax transaction manager endpoint of ARD. An attacker can...
CVE-2025-55886MEDIUM6.5An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ARD. The flaw exists in the `fe_uid` paramete...
CVE-2025-55885MEDIUM6.3SQL Injection vulnerability in Alpes Recherche et Developpement ARD GEC en Lign before v.2025-04-23 allows a remote atta...
CVE-2025-43953HIGH8.8In 2wcom IP-4c 2.16, the web interface allows admin and manager users to execute arbitrary code as root via a ping or tr...
CVE-2025-10809CRITICAL9.8A security vulnerability has been detected in Campcodes Online Learning Management System 1.0. The affected element is a...
CVE-2025-10808CRITICAL9.8A weakness has been identified in Campcodes Farm Management System 1.0. Impacted is an unknown function of the file /upl...
CVE-2025-59413MEDIUM6.5CubeCart is an ecommerce software solution. Prior to version 6.5.11, a logic flaw exists in the newsletter subscription ...
CVE-2025-59412MEDIUM5.4CubeCart is an ecommerce software solution. Prior to version 6.5.11, a vulnerability exists in the product reviews featu...
CVE-2025-59411MEDIUM5.4CubeCart is an ecommerce software solution. Prior to version 6.5.11, the contact form’s Enquiry field accepts raw HTML a...
CVE-2025-59335HIGH7.1CubeCart is an ecommerce software solution. Prior to version 6.5.11, there is an absence of automatic session expiration...
CVE-2025-57434HIGH8.8Creacast Creabox Manager contains a critical authentication flaw that allows an attacker to bypass login validation. The...
CVE-2025-57431HIGH8.8The Sound4 PULSE-ECO AES67 1.22 web-based management interface is vulnerable to Remote Code Execution (RCE) via a malici...
CVE-2025-43807MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in the notifications widget in Liferay Portal 7.4.0 through 7.4.3.112, a...
CVE-2025-10807HIGH8.8A security flaw has been discovered in Campcodes Online Beauty Parlor Management System 1.0. This issue affects some unk...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now