2025 CVE Vulnerabilities

45,233 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-37124HIGH8.6A vulnerability in the HPE Aruba Networking SD-WAN Gateways could allow an unauthenticated remote attacker to bypass fir...
CVE-2025-37123HIGH8.8A vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authent...
CVE-2025-9708MEDIUM6.8A vulnerability exists in the Kubernetes C# client where the certificate validation logic accepts properly constructed c...
CVE-2025-43805MEDIUM5.3Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92...
CVE-2025-10566MEDIUM6.1A vulnerability was identified in Campcodes Grocery Sales and Inventory System 1.0. Affected by this issue is some unkno...
CVE-2025-54391CRITICAL9.1A vulnerability in the EnableTwoFactorAuthRequest SOAP endpoint of Zimbra Collaboration (ZCS) allows an attacker with va...
CVE-2025-10565CRITICAL9.8A vulnerability was determined in Campcodes Grocery Sales and Inventory System 1.0. Affected by this vulnerability is an...
CVE-2025-10564CRITICAL9.8A vulnerability was found in Campcodes Grocery Sales and Inventory System 1.0. Affected is an unknown function of the fi...
CVE-2025-57631CRITICAL9.8SQL Injection vulnerability in TDuckCloud v.5.1 allows a remote attacker to execute arbitrary code via the Add a file up...
CVE-2025-56264HIGH7.5The /api/comment endpoint in zhangyd-c OneBlog 2.3.9 contains a denial-of-service vulnerability.
CVE-2025-56263HIGH8.8by-night sms V1.0 has an Arbitrary File Upload vulnerability. The /api/sms/upload/headImg endpoint allows uploading arbi...
CVE-2025-34187HIGH8.8Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a misconfiguration in the sudoers file that allows passwordless...
CVE-2025-34186CRITICAL9.8Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized in...
CVE-2025-34185HIGH7.5Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a pre-authentication file disclosure vulnerability via the 'db_log...
CVE-2025-34184CRITICAL9.8Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax...
CVE-2025-34183HIGH7.5Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows u...
CVE-2025-10563CRITICAL9.8A vulnerability has been found in Campcodes Grocery Sales and Inventory System 1.0. This impacts an unknown function of ...
CVE-2025-56557CRITICAL9.1An issue discovered in the Tuya Smart Life App 5.6.1 allows attackers to unprivileged control Matter devices via the Mat...
CVE-2025-49728MEDIUM4Cleartext storage of sensitive information in Microsoft PC Manager allows an unauthorized attacker to bypass a security ...
CVE-2025-47967MEDIUM4.7Insufficient ui warning of dangerous operations in Microsoft Edge for Android allows an unauthorized attacker to perform...
CVE-2025-10562CRITICAL9.8A flaw has been found in Campcodes Grocery Sales and Inventory System 1.0. This affects an unknown function of the file ...
CVE-2025-57625HIGH8.8CYRISMA Sensor before 444 for Windows has an Insecure Folder and File Permissions vulnerability. A low-privileged user c...
CVE-2025-57624HIGH7.8A DLL hijacking vulnerability in CYRISMA Agent before 444 allows local users to escalate privileges and execute arbitrar...
CVE-2025-56562HIGH7.5An incorrect API discovered in Signify Wiz Connected 1.9.1 allows attackers to remotely launch a DoS on Wiz devices only...
CVE-2025-54262HIGH7.8Substance3D - Stager versions 3.1.3 and earlier are affected by an out-of-bounds read vulnerability when parsing a craft...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now