2025 CVE Vulnerabilities

45,254 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-50986MEDIUM5.6diskover-web v2.3.0 Community Edition suffers from multiple stored cross-site scripting (XSS) vulnerabilities in its adm...
CVE-2025-50985MEDIUM5.6diskover-web v2.3.0 Community Edition is vulnerable to multiple reflected cross-site scripting (XSS) flaws in its web in...
CVE-2025-50972CRITICAL9.8SQL Injection vulnerability in AbanteCart 1.4.2, allows unauthenticated attackers to execute arbitrary SQL commands via ...
CVE-2025-9532HIGH8.8A flaw has been found in Portabilis i-Educar up to 2.10. This impacts an unknown function of the file /RegraAvaliacao/vi...
CVE-2025-9531HIGH8.8A vulnerability was detected in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/a...
CVE-2025-9529HIGH7.2A weakness has been identified in Campcodes Payroll Management System 1.0. The affected element is the function include ...
CVE-2025-9528HIGH7.2A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the function systemCommand of th...
CVE-2025-9527HIGH8.8A vulnerability was found in Linksys E1700 1.0.0.4.003. This affects the function QoSSetup of the file /goform/QoSSetup....
CVE-2025-56694MEDIUM5.8Client-side password validation (CWE-602) in lumasoft fotoShare Cloud 2025-03-13 allowing unauthenticated attackers to v...
CVE-2025-43882HIGH7.8Dell ThinOS 10, versions prior to 2508_10.0127, contains an Unverified Ownership vulnerability. A local low-privileged a...
CVE-2025-43730HIGH7.8Dell ThinOS 10, versions prior to 2508_10.0127, contains an Improper Neutralization of Argument Delimiters in a Command ...
CVE-2025-43729HIGH7.8Dell ThinOS 10, versions prior to 2508_10.0127, contains an Incorrect Permission Assignment for Critical Resource vulner...
CVE-2025-43728CRITICAL9.8Dell ThinOS 10, versions prior to 2508_10.0127, contain a Protection Mechanism Failure vulnerability. An unauthenticated...
CVE-2025-9526HIGH8.8A vulnerability has been found in Linksys E1700 1.0.0.4.003. Affected by this issue is the function setSysAdm of the fil...
CVE-2025-9525HIGH8.8A flaw has been found in Linksys E1700 1.0.0.4.003. Affected by this vulnerability is the function setWan of the file /g...
CVE-2025-9523CRITICAL9.8A vulnerability was detected in Tenda AC1206 15.03.06.23. Affected is the function GetParentControlInfo of the file /gof...
CVE-2025-30064HIGH8.8An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function chec...
CVE-2025-30063CRITICAL9.4The configuration file containing database logins and passwords is readable by any local user.
CVE-2025-30061MEDIUM6.9In the "utils/Reporter/OpenReportWindow.pl" service, there is an SQL injection vulnerability through the "UserID" parame...
CVE-2025-30060MEDIUM6.9In the ReturnUserUnitsXML.pl service, the "getUserInfo" function is vulnerable to SQL injection through the "UserID" par...
CVE-2025-30059MEDIUM6.9In the PrepareCDExportJSON.pl service, the "getPerfServiceIds" function is vulnerable to SQL injection.
CVE-2025-30058MEDIUM6.9In the PatientService.pl service, the "getPatientIdentifier" function is vulnerable to SQL injection through the "pesel"...
CVE-2025-30057CRITICAL9.4In UHCRTFDoc, the filename parameter can be exploited to execute arbitrary code via command injection into the system() ...
CVE-2025-30056CRITICAL9.4The RunCommand function accepts any parameter, which is then passed for execution in the shell. This allows an attacker ...
CVE-2025-30055CRITICAL9The "system" function receives untrusted input from the user. If the "EnableJSCaching" option is enabled, it is possible...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now