2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-41078HIGH8.1Weaknesses in the authorization mechanisms of Viafirma Documents v3.7.129 allow an authenticated user without privileges...
CVE-2025-41077HIGH8.1IDOR vulnerability has been found in Viafirma Inbox v4.5.13 that allows any authenticated user without privileges in the...
CVE-2025-41005HIGH8.7Imaster's MEMS Events CRM contains an SQL injection vulnerability in‘keyword’ parameter in ‘/memsdemo/exchange_offers.ph...
CVE-2025-41004HIGH8.7Imaster's Patient Records Management System is vulnerable to SQL Injection in the endpoint ‘/projects/hospital/admin/com...
CVE-2025-14279HIGH8.1MLFlow versions up to and including 3.4.0 are vulnerable to DNS rebinding attacks due to a lack of Origin header validat...
CVE-2025-69276HIGH8.8Deserialization of Untrusted Data vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Object Injection...
CVE-2025-69274HIGH8.8Authorization Bypass Through User-Controlled Key vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows P...
CVE-2025-69273HIGH7.5Improper Authentication vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Authentication Bypass.This...
CVE-2025-69272HIGH7.5Cleartext Transmission of Sensitive Information vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sn...
CVE-2025-69271HIGH7.5Insufficiently Protected Credentials vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Atta...
CVE-2025-68493HIGH8.1Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 befo...
CVE-2025-62235HIGH8.1Authentication Bypass by Spoofing vulnerability in Apache NimBLE. Receiving specially crafted Security Request could le...
CVE-2025-53477HIGH7.5NULL Pointer Dereference vulnerability in Apache Nimble. Missing validation of HCI connection complete or HCI command T...
CVE-2025-52435HIGH7.5J2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE. Improper handling of Pause ...
CVE-2025-13457HIGH7.5The WooCommerce Square plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and...
CVE-2025-59057HIGH7.6React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 ...
CVE-2025-67070HIGH8.2A vulnerability exists in Intelbras CFTV IP NVD 9032 R Ftd V2.800.00IB00C.0.T, which allows an unauthenticated attacker ...
CVE-2025-66744HIGH7.5In Yonyou YonBIP v3 and before, the LoginWithV8 interface in the series data application service system is vulnerable to...
CVE-2025-46645HIGH7.2Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4....
CVE-2025-15495HIGH7.2A vulnerability was found in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admin/editsite...
CVE-2025-15494HIGH8.8A vulnerability has been found in RainyGao DocSys up to 2.02.37. This affects an unknown function of the file com/DocSys...
CVE-2025-15035HIGH7.3Improper Input Validation vulnerability in TP-Link Archer AXE75 v1.6 (vpn modules) allows an authenticated adjacent atta...
CVE-2025-67133HIGH7.5An issue in Hero Motocorp Vida V1 Pro 2.0.7 allows a local attacker to cause a denial of service via the BLE component
CVE-2025-56225HIGH7.5fluidsynth-2.4.6 and earlier versions is vulnerable to Null pointer dereference in fluid_synth_monopoly.c, that can be t...
CVE-2025-15492HIGH8.8A vulnerability was detected in RainyGao DocSys up to 2.02.36. The affected element is an unknown function of the file s...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now