2025 CVE Vulnerabilities

45,246 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-55727CRITICAL9.8XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in ...
CVE-2025-55052MEDIUM4.3CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVE-2025-55051CRITICAL10CWE-1392: Use of Default Credentials
CVE-2025-55050CRITICAL9.8CWE-1242: Inclusion of Undocumented Features
CVE-2025-55049CRITICAL9.1Use of Default Cryptographic Key (CWE-1394)
CVE-2025-55048CRITICAL9.8Multiple CWE-78
CVE-2025-55047HIGH8.4CWE-798 Use of Hard-coded Credentials
CVE-2025-54256HIGH8.6Dreamweaver Desktop versions 21.5 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that cou...
CVE-2025-54242HIGH7.8Premiere Pro versions 25.3, 24.6.5 and earlier are affected by a Use After Free vulnerability that could result in arbit...
CVE-2025-43781MEDIUM6.1Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.110 through 7.4.3.128, and Liferay DXP 2024.Q...
CVE-2025-43775MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 thr...
CVE-2025-29089HIGH7.5An issue in TP-Link AX10 Ax1500 v.1.3.10 Build (20230130) allows a remote attacker to obtain sensitive information
CVE-2025-10164HIGH7.3A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the fi...
CVE-2025-9269MEDIUM6.9A Server-Side Request Forgery (SSRF) vulnerability has been identified in the embedded web server in various Lexmark dev...
CVE-2025-57665MEDIUM6.4Element Plus Link component (el-link) through 2.10.6 implements insufficient input validation for the href attribute, cr...
CVE-2025-57086HIGH7.5Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the String parameter in the formDeleteMeshNo...
CVE-2025-57085CRITICAL9.8Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the v17 parameter in the UploadCfg function....
CVE-2025-57078HIGH7.5Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the pppoeServerWhiteMacIndex parameter in the ...
CVE-2025-10199HIGH7.8A local privilege escalation vulnerability exists in Sunshine for Windows (version v2025.122.141614 and likely prior ver...
CVE-2025-10198HIGH7.8Sunshine for Windows, version v2025.122.141614, contains a DLL search-order hijacking vulnerability, allowing attackers ...
CVE-2025-5500MEDIUM5.3A flaw has been found in ZhenShi Mibro Fit App 1.6.3.17499 on Android. This impacts an unknown function of the file Andr...
CVE-2025-5005HIGH7.3A vulnerability was detected in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.5.4. This affects an unk...
CVE-2025-59008HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PressTigers ZIP Co...
CVE-2025-59005MEDIUM4.3Missing Authorization vulnerability in frenify Categorify categorify allows Exploiting Incorrectly Configured Access Con...
CVE-2025-58997CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in Frenify Mow mow allows Code Injection.This issue affects Mow: from n/...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now