2025 CVE Vulnerabilities
45,254 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-50986 | MEDIUM | 5.6 | 0.2% | Aug 27, 2025 | diskover-web v2.3.0 Community Edition suffers from multiple stored cross-site scripting (XSS) vulnerabilities in its adm... |
| CVE-2025-50985 | MEDIUM | 5.6 | 0.2% | Aug 27, 2025 | diskover-web v2.3.0 Community Edition is vulnerable to multiple reflected cross-site scripting (XSS) flaws in its web in... |
| CVE-2025-50972 | CRITICAL | 9.8 | 0.4% | Aug 27, 2025 | SQL Injection vulnerability in AbanteCart 1.4.2, allows unauthenticated attackers to execute arbitrary SQL commands via ... |
| CVE-2025-9532 | HIGH | 8.8 | 0.4% | Aug 27, 2025 | A flaw has been found in Portabilis i-Educar up to 2.10. This impacts an unknown function of the file /RegraAvaliacao/vi... |
| CVE-2025-9531 | HIGH | 8.8 | 0.4% | Aug 27, 2025 | A vulnerability was detected in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/a... |
| CVE-2025-9529 | HIGH | 7.2 | 0.5% | Aug 27, 2025 | A weakness has been identified in Campcodes Payroll Management System 1.0. The affected element is the function include ... |
| CVE-2025-9528 | HIGH | 7.2 | 50.1% | Aug 27, 2025 | A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the function systemCommand of th... |
| CVE-2025-9527 | HIGH | 8.8 | 1.3% | Aug 27, 2025 | A vulnerability was found in Linksys E1700 1.0.0.4.003. This affects the function QoSSetup of the file /goform/QoSSetup.... |
| CVE-2025-56694 | MEDIUM | 5.8 | 0.4% | Aug 27, 2025 | Client-side password validation (CWE-602) in lumasoft fotoShare Cloud 2025-03-13 allowing unauthenticated attackers to v... |
| CVE-2025-43882 | HIGH | 7.8 | 0.1% | Aug 27, 2025 | Dell ThinOS 10, versions prior to 2508_10.0127, contains an Unverified Ownership vulnerability. A local low-privileged a... |
| CVE-2025-43730 | HIGH | 7.8 | 0.2% | Aug 27, 2025 | Dell ThinOS 10, versions prior to 2508_10.0127, contains an Improper Neutralization of Argument Delimiters in a Command ... |
| CVE-2025-43729 | HIGH | 7.8 | 0.1% | Aug 27, 2025 | Dell ThinOS 10, versions prior to 2508_10.0127, contains an Incorrect Permission Assignment for Critical Resource vulner... |
| CVE-2025-43728 | CRITICAL | 9.8 | 0.3% | Aug 27, 2025 | Dell ThinOS 10, versions prior to 2508_10.0127, contain a Protection Mechanism Failure vulnerability. An unauthenticated... |
| CVE-2025-9526 | HIGH | 8.8 | 1.3% | Aug 27, 2025 | A vulnerability has been found in Linksys E1700 1.0.0.4.003. Affected by this issue is the function setSysAdm of the fil... |
| CVE-2025-9525 | HIGH | 8.8 | 1.3% | Aug 27, 2025 | A flaw has been found in Linksys E1700 1.0.0.4.003. Affected by this vulnerability is the function setWan of the file /g... |
| CVE-2025-9523 | CRITICAL | 9.8 | 1.0% | Aug 27, 2025 | A vulnerability was detected in Tenda AC1206 15.03.06.23. Affected is the function GetParentControlInfo of the file /gof... |
| CVE-2025-30064 | HIGH | 8.8 | 0.1% | Aug 27, 2025 | An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function chec... |
| CVE-2025-30063 | CRITICAL | 9.4 | 0.1% | Aug 27, 2025 | The configuration file containing database logins and passwords is readable by any local user. |
| CVE-2025-30061 | MEDIUM | 6.9 | 0.2% | Aug 27, 2025 | In the "utils/Reporter/OpenReportWindow.pl" service, there is an SQL injection vulnerability through the "UserID" parame... |
| CVE-2025-30060 | MEDIUM | 6.9 | 0.2% | Aug 27, 2025 | In the ReturnUserUnitsXML.pl service, the "getUserInfo" function is vulnerable to SQL injection through the "UserID" par... |
| CVE-2025-30059 | MEDIUM | 6.9 | 0.2% | Aug 27, 2025 | In the PrepareCDExportJSON.pl service, the "getPerfServiceIds" function is vulnerable to SQL injection. |
| CVE-2025-30058 | MEDIUM | 6.9 | 0.2% | Aug 27, 2025 | In the PatientService.pl service, the "getPatientIdentifier" function is vulnerable to SQL injection through the "pesel"... |
| CVE-2025-30057 | CRITICAL | 9.4 | 0.7% | Aug 27, 2025 | In UHCRTFDoc, the filename parameter can be exploited to execute arbitrary code via command injection into the system() ... |
| CVE-2025-30056 | CRITICAL | 9.4 | 0.2% | Aug 27, 2025 | The RunCommand function accepts any parameter, which is then passed for execution in the shell. This allows an attacker ... |
| CVE-2025-30055 | CRITICAL | 9 | 0.2% | Aug 27, 2025 | The "system" function receives untrusted input from the user. If the "EnableJSCaching" option is enabled, it is possible... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now