2025 CVE Vulnerabilities

45,252 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-9696CRITICAL9.4The SunPower PVS6's BluetoothLE interface is vulnerable due to its use of hardcoded encryption parameters and publicly a...
CVE-2025-55474MEDIUM6.1Many Notes 0.10.1 is vulnerable to Cross Site Scripting (XSS), which allows malicious Markdown files to execute JavaScri...
CVE-2025-55473MEDIUM6.1Asian Arts Talents Foundation (AATF) Website v5.1.x and Docker version 2024.12.8.1 are vulnerable to Cross Site Scriptin...
CVE-2025-55472MEDIUM6.5SQL Injection vulnerability exists in Tirreno v0.9.5, specifically in the /admin/loadUsers API endpoint. The vulnerabili...
CVE-2025-55373MEDIUM5.3Incorrect access control in Beakon Application before v5.4.3 allows authenticated attackers with low-level privileges to...
CVE-2025-57616HIGH7.5An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A use-after-free vulnerability in the write_interleav...
CVE-2025-57615HIGH7.5An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) An integer overflow vulnerability in the Vector::new ...
CVE-2025-57614HIGH7.5An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Integer overflow and invalid input vulnerability in t...
CVE-2025-57613HIGH7.5An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A null pointer dereference vulnerability in the input...
CVE-2025-57612HIGH7.5An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Null pointer dereference vulnerability in the name() ...
CVE-2025-57611MEDIUM5.3An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Null pointer dereference vulnerability in the dump() ...
CVE-2025-55372MEDIUM5.3An arbitrary file upload vulnerability in Beakon Application before v5.4.3 allows attackers to execute arbitrary code vi...
CVE-2025-54599HIGH7.5The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows account takeover,...
CVE-2025-50757MEDIUM6.5Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the user...
CVE-2025-50755MEDIUM6.5Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_cmd function via the comm...
CVE-2025-9784HIGH7.5A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering ab...
CVE-2025-46047MEDIUM6.5A User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows...
CVE-2025-2413HIGH8.6Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft ProKuafor allows Authentication Bypa...
CVE-2025-0670MEDIUM4.7Authorization Bypass Through User-Controlled Key vulnerability in Akinsoft ProKuafor allows Resource Leak Exposure. Thi...
CVE-2025-6519CRITICAL9.8E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily generated password. An at...
CVE-2025-5662CRITICAL9.8A deserialization vulnerability exists in the H2O-3 REST API (POST /99/ImportSQLTable) that affects all versions up to 3...
CVE-2025-57140CRITICAL9.8rsbi-pom 4.7 is vulnerable to SQL Injection in the /bi/service/model/DatasetService path.
CVE-2025-56254MEDIUM4.3PHPGurukul Employee Leave Management System 2.1 contains an Insecure Direct Object Reference (IDOR) vulnerability in lea...
CVE-2025-52551CRITICAL9.3E2 Facility Management Systems use a proprietary protocol that allows for unauthenticated file operations on any file in...
CVE-2025-52550HIGH7.2E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned. An attacker can forge ma...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now