2025 CVE Vulnerabilities

45,254 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-50977MEDIUM6.1A template injection vulnerability leading to reflected cross-site scripting (XSS) has been identified in version 1.7.1,...
CVE-2025-50428CRITICAL9.8In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. ...
CVE-2025-34161HIGH8.8Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deplo...
CVE-2025-34159HIGH8.8Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application d...
CVE-2025-34157CRITICAL9Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project ...
CVE-2025-20348MEDIUM5A vulnerability in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller (NDFC) co...
CVE-2025-20347MEDIUM5.4A vulnerability in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller (NDFC) co...
CVE-2025-20344HIGH7.2A vulnerability in the backup restore functionality of Cisco Nexus Dashboard could allow an authenticated, remote attack...
CVE-2025-20342MEDIUM5.4A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controll...
CVE-2025-20317HIGH7.1A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controll...
CVE-2025-20296MEDIUM5.4A vulnerability in the web-based management interface of Cisco UCS Manager Software could allow an authenticated, remote...
CVE-2025-20295MEDIUM6A vulnerability in the CLI of Cisco UCS Manager Software could allow an authenticated, local attacker with administrativ...
CVE-2025-20294MEDIUM6.5Multiple vulnerabilities in the CLI and web-based management interface of Cisco UCS Manager Software could allow an auth...
CVE-2025-20292MEDIUM4.4A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute a command inj...
CVE-2025-20290MEDIUM5.5A vulnerability in the logging feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches, Cisco Nexus 9000 Se...
CVE-2025-20262MEDIUM5A vulnerability in the Protocol Independent Multicast Version 6 (PIM6) feature of Cisco Nexus 3000 Series Switches and C...
CVE-2025-20241HIGH7.4A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) feature of Cisco NX-OS Software for Cisco Nexu...
CVE-2025-54598MEDIUM6.5The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows CSRF to delete al...
CVE-2025-50984MEDIUM5.3diskover-web v2.3.0 Community Edition is vulnerable to multiple boolean-based blind SQL injection flaws in its Elasticse...
CVE-2025-50983HIGH8.3SQL Injection vulnerability exists in the sortKey parameter of the GET /api/v1/wanted/cutoff API endpoint in readarr 0.4...
CVE-2025-50978MEDIUM6.1In Gitblit v1.7.1, a reflected cross-site scripting (XSS) vulnerability exists in the way repository path names are hand...
CVE-2025-9533CRITICAL9.8A vulnerability has been found in TOTOLINK T10 4.1.8cu.5241_B20210927. Affected is an unknown function of the file /form...
CVE-2025-53105HIGH7.5GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that...
CVE-2025-52122CRITICAL9.8Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability...
CVE-2025-50989CRITICAL9.1OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now