2025 CVE Vulnerabilities

45,253 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-58067MEDIUM4.2Basecamp's Google Sign-In adds Google sign-in to Rails applications. Prior to version 1.3.1, it is possible to redirect ...
CVE-2025-58066MEDIUM5.3nptd-rs is a tool for synchronizing your computer's clock, implementing the NTP and NTS protocols. In versions between 1...
CVE-2025-9673MEDIUM5.3A vulnerability was detected in Kakao 헤이카카오 Hey Kakao App up to 2.17.4 on Android. Affected by this vulnerability is an ...
CVE-2025-9672MEDIUM5.3A security vulnerability has been detected in Rejseplanen App up to 8.2.2. Affected is an unknown function of the file A...
CVE-2025-9671MEDIUM5.3A weakness has been identified in UAB Paytend App up to 2.1.9 on Android. This impacts an unknown function of the file A...
CVE-2025-56577HIGH8.4An issue in Evope Core v.1.1.3.20 allows a local attacker to obtain sensitive information via the use of hard coded cryp...
CVE-2025-9670MEDIUM5.5A security flaw has been discovered in mixmark-io turndown up to 7.2.1. This affects an unknown function of the file src...
CVE-2025-9669CRITICAL9.8A vulnerability has been found in Jinher OA 1.0. This issue affects some unknown processing of the file GetTreeDate.aspx...
CVE-2025-9667HIGH8.8A vulnerability was detected in code-projects Simple Grading System 1.0. This affects an unknown part of the file /delet...
CVE-2025-43773CRITICAL9.1Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024...
CVE-2025-9666HIGH8.8A security vulnerability has been detected in code-projects Simple Grading System 1.0. Affected by this issue is some un...
CVE-2025-9665HIGH8.8A weakness has been identified in code-projects Simple Grading System 1.0. Affected by this vulnerability is an unknown ...
CVE-2025-9377HIGH7.2The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7...
CVE-2025-58158HIGH8.8Harness Open Source is an end-to-end developer platform with Source Control Management, CI/CD Pipelines, Hosted Develope...
CVE-2025-52861HIGH7A path traversal vulnerability has been reported to affect VioStor. If a remote attacker gains an administrator account,...
CVE-2025-52856CRITICAL9.8An improper authentication vulnerability has been reported to affect VioStor. If a remote attacker, they can then exploi...
CVE-2025-44033CRITICAL9.8SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute arbitrary code via the allDirec...
CVE-2025-44015HIGH8.4A command injection vulnerability has been reported to affect HybridDesk Station. If an attacker gains local network acc...
CVE-2025-33038MEDIUM6.5A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the...
CVE-2025-33037MEDIUM6.5A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the...
CVE-2025-33036MEDIUM6.5A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the...
CVE-2025-33033MEDIUM6.5A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the...
CVE-2025-33032MEDIUM4.9A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker ...
CVE-2025-30278HIGH8.8An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a...
CVE-2025-30277HIGH8.8An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now