2025 CVE Vulnerabilities

45,252 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-52549CRITICAL9.8E3 Site Supervisor Control (firmware version < 2.31F01) generates the root linux password on each boot. An attacker can ...
CVE-2025-52548MEDIUM4.9E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enab...
CVE-2025-52547HIGH7.5E3 Site Supervisor Control (firmware version < 2.31F01) MGW contains an API call that lacks input validation. An attacke...
CVE-2025-52546MEDIUM6.1E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated atta...
CVE-2025-52545HIGH7.5E3 Site Supervisor Control (firmware version < 2.31F01) RCI service contains an API call to read users info, which retur...
CVE-2025-52544HIGH7.5E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated atta...
CVE-2025-52543HIGH7.5E3 Site Supervisor Control (firmware version < 2.31F01) application services (MGW and RCI) uses client side hashing for ...
CVE-2025-46810HIGH8.5A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of openSUSE Tumbleweed traefik2 allows the traef...
CVE-2025-2414HIGH8.6Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft OctoCloud allows Authentication Bypa...
CVE-2025-0640MEDIUM4.7Authorization Bypass Through User-Controlled Key vulnerability in Akinsoft OctoCloud allows Resource Leak Exposure. Thi...
CVE-2025-9573HIGH8.6The ns_backup extension through 13.0.2 for TYPO3 allows command injection.
CVE-2025-41031MEDIUM6.9Lack of authorisation in Deporsite by T-INNOVA. This vulnerability allows an unauthenticated attacker to change other us...
CVE-2025-41030MEDIUM6.9Lack of authorisation in Deporsite by T-INNOVA. This vulnerability allows an unauthenticated attacker to obtain informat...
CVE-2025-44017MEDIUM5.1"Gunosy" App contains a vulnerability where sensitive information may be included in the application's outbound communic...
CVE-2025-41690HIGH7.4A low-privileged attacker in bluetooth range may be able to access the password of a higher-privilege user (Maintenance)...
CVE-2025-9815HIGH7.8A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS. The affected element is an unknown function o...
CVE-2025-9814CRITICAL9.8A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. Impacted is an unknown function ...
CVE-2025-9813HIGH8.8A vulnerability was identified in Tenda CH22 1.0.0.1. This issue affects the function formSetSambaConf of the file /gofo...
CVE-2025-9812HIGH8.8A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formexeCommand of the file...
CVE-2025-9811CRITICAL9.8A vulnerability was found in Campcodes Farm Management System 1.0. This affects an unknown part of the file /reviewInput...
CVE-2025-8662MEDIUM4.3OpenAM (OpenAM Consortium Edition) contains a vulnerability that may cause it to malfunction as a SAML IdP due to a tamp...
CVE-2025-58421Rejected reason: Not used
CVE-2025-58420Rejected reason: Not used
CVE-2025-58419Rejected reason: Not used
CVE-2025-58418Rejected reason: Not used

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now