2025 CVE Vulnerabilities

45,233 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-59358HIGH7.5The Chaos Controller Manager in Chaos Mesh exposes a GraphQL debugging server without authentication to the entire Kuber...
CVE-2025-43794MEDIUM4.8Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported version...
CVE-2025-10444CRITICAL9.8A security flaw has been discovered in Campcodes Online Job Finder System 1.0. This issue affects some unknown processin...
CVE-2025-10443HIGH8.8A vulnerability was identified in Tenda AC9 and AC15 15.03.05.14/15.03.05.18. This vulnerability affects the function fo...
CVE-2025-9826MEDIUM5.4Stored cross-site scripting vulnerability in M-Files Hubshare before version 25.8 allows authenticated attackers to caus...
CVE-2025-9084MEDIUM6.1Mattermost versions 10.5.x <= 10.5.9 fail to properly validate redirect URLs which allows attackers to redirect users to...
CVE-2025-9072MEDIUM5.4Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redirect_to parameter, a...
CVE-2025-10442HIGH8.8A vulnerability was determined in Tenda AC9 and AC15 15.03.05.14. This affects the function formexeCommand of the file /...
CVE-2025-10441MEDIUM6.3A vulnerability was found in D-Link DI-8100G, DI-8200G and DI-8003G 17.12.20A1/19.12.10A1. Affected by this issue is the...
CVE-2025-9078MEDIUM4.3Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to ...
CVE-2025-9076MEDIUM6.5Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronizat...
CVE-2025-10440MEDIUM6.3A vulnerability has been found in D-Link DI-8100, DI-8100G, DI-8200, DI-8200G, DI-8003 and DI-8003G 16.07.26A1/17.12.20A...
CVE-2025-10436CRITICAL9.8A weakness has been identified in Campcodes Computer Sales and Inventory System 1.0. The impacted element is an unknown ...
CVE-2025-10435CRITICAL9.8A security flaw has been discovered in Campcodes Computer Sales and Inventory System 1.0. The affected element is an unk...
CVE-2025-10434LOW2.4A vulnerability was identified in IbuyuCMS up to 2.6.3. Impacted is an unknown function of the file /admin/article.php?a...
CVE-2025-41713MEDIUM6.5During a short time frame while the device is booting an unauthenticated remote attacker can send traffic to unauthorize...
CVE-2025-10433MEDIUM6.3A vulnerability was determined in 1Panel-dev MaxKB up to 2.0.2/2.1.0. This issue affects some unknown processing of the ...
CVE-2025-10432CRITICAL9.8A vulnerability was found in Tenda AC1206 15.03.06.23. This vulnerability affects the function check_param_changed of th...
CVE-2025-10431HIGH8.8A vulnerability has been found in SourceCodester Pet Grooming Management Software 1.0. This affects an unknown part of t...
CVE-2025-10430HIGH8.8A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected by this issue is some unknown fun...
CVE-2025-59378MEDIUM5.7In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program th...
CVE-2025-10453MEDIUM6.9O'View MapServer developed by PilotGaea Technologies has a Server-Side Request Forgery vulnerability, allowing unauthent...
CVE-2025-10429HIGH8.8A vulnerability was detected in SourceCodester Pet Grooming Management Software 1.0. Affected by this vulnerability is a...
CVE-2025-10428HIGH8.8A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknow...
CVE-2025-10427HIGH8.8A weakness has been identified in SourceCodester Pet Grooming Management Software 1.0. This impacts an unknown function ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now