2025 CVE Vulnerabilities

45,251 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-55162HIGH8.8Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In vers...
CVE-2025-53690CRITICAL9Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) a...
CVE-2025-9924CRITICAL9.8A vulnerability has been found in projectworlds Travel Management System 1.0. This vulnerability affects unknown code of...
CVE-2025-9923MEDIUM6.1A flaw has been found in Campcodes Sales and Inventory System 1.0. This affects an unknown part of the file /index.php. ...
CVE-2025-36193MEDIUM6.7IBM Transformation Advisor 2.0.1 through 4.3.1 incorrectly assigns privileges to security critical files which could all...
CVE-2025-56803HIGH8.4Figma Desktop for Windows version 125.6.5 contains a command injection vulnerability in the local plugin loader. An atta...
CVE-2025-56752CRITICAL9.4A vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote attackers to fully bypass auth...
CVE-2025-52494HIGH7.5Adacore Ada Web Server (AWS) before 25.2 is vulnerable to a denial-of-service (DoS) condition due to improper handling o...
CVE-2025-45805HIGH7.6In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript cod...
CVE-2025-20336HIGH7.5A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and C...
CVE-2025-20335MEDIUM5.3A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and C...
CVE-2025-20330MEDIUM6.1A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service ...
CVE-2025-20328MEDIUM5.4A vulnerability in the user profile component of Cisco Webex Meetings could have allowed an authenticated, remote attack...
CVE-2025-20326HIGH8.8A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and ...
CVE-2025-20291MEDIUM6.1A vulnerability in Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to redirect a targeted We...
CVE-2025-20287HIGH8.8A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow a...
CVE-2025-20280MEDIUM4.8A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri...
CVE-2025-20270MEDIUM6.5A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri...
CVE-2025-9959HIGH7.6Incomplete validation of dunder attributes allows an attacker to escape from the Local Python execution environment sand...
CVE-2025-9922MEDIUM6.1A security vulnerability has been detected in Campcodes Sales and Inventory System 1.0. Affected by this vulnerability i...
CVE-2025-9921MEDIUM5.4A weakness has been identified in code-projects POS Pharmacy System 1.0. Affected is an unknown function of the file /ma...
CVE-2025-9867MEDIUM5.4Inappropriate implementation in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker t...
CVE-2025-9866HIGH8.8Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to bypass c...
CVE-2025-9865MEDIUM5.4Inappropriate implementation in Toolbar in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker who...
CVE-2025-9864Rejected reason: This CVE ID was assigned in error to a vulnerability that was both introduced and fixed before the code...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now