2025 CVE Vulnerabilities

45,233 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-54807CRITICAL9.8The secret used for validating authentication tokens is hardcoded in device firmware for affected versions. An attacker...
CVE-2025-54754HIGH8.6An attacker with adjacent access, without authentication, can exploit this vulnerability to retrieve a hard-coded passw...
CVE-2025-53947HIGH7.7A local attacker with low privileges on the Windows system where the software is installed can exploit this vulnerabili...
CVE-2025-47698HIGH8.6An adjacent attacker without authentication can exploit this vulnerability to retrieve a set of user-privileged credenti...
CVE-2025-30519CRITICAL9.8Dover Fueling Solutions ProGauge MagLink LX4 Devices have default root credentials that cannot be changed through standa...
CVE-2025-10689CRITICAL9.8A vulnerability was identified in D-Link DIR-645 105B01. This issue affects the function soapcgi_main of the file /soap....
CVE-2025-59424HIGH7.3LinkAce is a self-hosted archive to collect website links. Prior to 2.3.1, a Stored Cross-Site Scripting (XSS) vulnerabi...
CVE-2025-10688CRITICAL9.8A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknow...
CVE-2025-47906MEDIUM6.5If the PATH environment variable contains paths which are executables (rather than just directories), passing certain st...
CVE-2025-26503MEDIUM6.7A crafted system call argument can cause memory corruption.
CVE-2025-10650LOW1.8SoftIron HyperCloud 2.5.0 through 2.6.3 may incorrectly add user SSH keys to the administrator-level authorized keys und...
CVE-2025-10687CRITICAL9.8A vulnerability was found in SourceCodester Responsive E-Learning System 1.0. This affects an unknown part of the file /...
CVE-2025-55912HIGH7.3An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in ...
CVE-2025-50255HIGH7.8Cross Site Request Forgery (CSRF) vulnerability in Smartvista BackOffice SmartVista Suite 2.2.22 via crafted GET request...
CVE-2025-36146MEDIUM4.3IBM Lakehouse (watsonx.data 2.2) could allow an authenticated user to obtain sensitive server component version informat...
CVE-2025-36143HIGH7.2IBM Lakehouse (watsonx.data 2.2) could allow an authenticated privileged user to execute arbitrary commands on the syste...
CVE-2025-36139MEDIUM4.8IBM Lakehouse (watsonx.data 2.2) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged us...
CVE-2025-10676MEDIUM4.3A weakness has been identified in fuyang_lipengjun platform 1.0. Affected is the function BrandController of the file /b...
CVE-2025-10675MEDIUM4.3A security flaw has been discovered in fuyang_lipengjun platform 1.0. This impacts the function AttributeController of t...
CVE-2025-10674MEDIUM4.3A vulnerability was identified in fuyang_lipengjun platform 1.0. This affects the function AttributeCategoryController o...
CVE-2025-59421LOW2.7Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-...
CVE-2025-59417MEDIUM6.1Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.129.4, there is a a cross-site sc...
CVE-2025-59040MEDIUM4.3Tuleap is an Open Source Suite to improve management of software developments and collaboration. Backlog item representa...
CVE-2025-57452MEDIUM6.1In realme BackupRestore app v15.1.12_2810c08_250314, improper URI scheme handling in com.coloros.pc.PcToolMainActivity a...
CVE-2025-55911MEDIUM6.5An issue Clip Bucket v.5.5.2 Build#90 allows a remote attacker to execute arbitrary codes via the file_downloader.php an...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now