2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-50858MEDIUM6.1Reflected Cross-Site Scripting in the List MySQL Databases function in Easy Hosting Control Panel (EHCP) 20.04.1.b allow...
CVE-2025-4650HIGH7.2User with high privileges is able to introduce a SQLi using the Meta Service indicator page. Caused by an Improper Neutr...
CVE-2025-43762MEDIUM6.5Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q...
CVE-2025-43759LOW2.7Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q...
CVE-2025-43758MEDIUM5.3Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q...
CVE-2025-55613CRITICAL9.8Tenda O3V2 1.0.0.12(3880) is vulnerable to Buffer Overflow in the fromSafeSetMacFilter function via the mac parameter.
CVE-2025-55581HIGH7.3D-Link DCS-825L firmware version 1.08.01 and possibly prior versions contain an insecure implementation in the mydlink-w...
CVE-2025-52287HIGH8.8OperaMasks SDK ELite Script Engine v0.5.0 was discovered to contain a deserialization vulnerability.
CVE-2025-52085HIGH8.8An SQL injection vulnerability in Yoosee application v6.32.4 allows authenticated users to inject arbitrary SQL queries ...
CVE-2025-43760MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025...
CVE-2025-57800HIGH8.8Audiobookshelf is an open-source self-hosted audiobook server. In versions 2.6.0 through 2.26.3, the application does no...
CVE-2025-57771HIGH8.1Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions prior to 3.25.5, Roo-Code fa...
CVE-2025-57770MEDIUM5.3The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Ve...
CVE-2025-57105CRITICAL9.8The DI-7400G+ router has a command injection vulnerability, which allows attackers to execute arbitrary commands on the ...
CVE-2025-55745HIGH8.8UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Versions 0.3.0 and ...
CVE-2025-55637CRITICAL9.8Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to contain a ...
CVE-2025-55634HIGH7.5Incorrect access control in the RTMP server settings of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firm...
CVE-2025-55631MEDIUM4Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to manage use...
CVE-2025-55630HIGH7.3A discrepancy in the error message returned by the login function of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with...
CVE-2025-55629MEDIUM6.5Insecure permissions in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allo...
CVE-2025-55627MEDIUM5.3Insufficient privilege verification in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_...
CVE-2025-55626MEDIUM5.3An Insecure Direct Object Reference (IDOR) vulnerability in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - ...
CVE-2025-55625MEDIUM6.3An open redirect vulnerability in Reolink v4.54.0.4.20250526 allows attackers to redirect users to a malicious site via ...
CVE-2025-55624MEDIUM5.3An intent redirection vulnerability in Reolink v4.54.0.4.20250526 allows unauthorized attackers to access internal funct...
CVE-2025-55623MEDIUM5.4An issue in the lock screen component of Reolink v4.54.0.4.20250526 allows attackers to bypass authentication via using ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now