2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-53763CRITICAL9.8Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-51989HIGH7HTML injection vulnerability in the registration interface in Evolution Consulting Kft. HRmaster module v235 allows an a...
CVE-2025-41415HIGH7.1The vulnerability, if exploited, could allow an authenticated miscreant (with privileges to access publication targets)...
CVE-2025-3128CRITICAL9.8A remote unauthenticated attacker who has bypassed authentication could execute arbitrary OS commands to disclose, tamp...
CVE-2025-27721HIGH8.7Unauthorized users can access INFINITT PACS System Manager without proper authorization, which could lead to unauthoriz...
CVE-2025-27714MEDIUM6.3An attacker could exploit this vulnerability by uploading arbitrary files via the a specific endpoint, leading to unaut...
CVE-2025-24489MEDIUM6.3An attacker could exploit this vulnerability by uploading arbitrary files via a specific service, which could lead to s...
CVE-2025-57751HIGH7.7pyLoad is the free and open-source Download Manager written in pure Python. The jk parameter is received in pyLoad CNL B...
CVE-2025-38743HIGH7.8Dell iDRAC Service Module (iSM), versions prior to 6.0.3.0, contains a Buffer Access with Incorrect Length Value vulnera...
CVE-2025-38742MEDIUM5.3Dell iDRAC Service Module (iSM), versions prior to 6.0.3.0, contains an Incorrect Permission Assignment for Critical Res...
CVE-2025-7051HIGH8.3On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers ...
CVE-2025-57768MEDIUM6.9Phproject is a high performance full-featured project management system. From 1.8.0 to before 1.8.3, a Stored Cross-Site...
CVE-2025-55524HIGH7.3Insecure permissions in Agent-Zero v0.8.* allow attackers to arbitrarily reset the system via unspecified vectors.
CVE-2025-55523LOW3.5An issue in the component /api/download_work_dir_file.py of Agent-Zero v0.8.* allows attackers to execute a directory tr...
CVE-2025-52352CRITICAL9.8Aikaan IoT management platform v3.25.0325-5-g2e9c59796 provides a configuration to disable user sign-up in distributed d...
CVE-2025-52351HIGH8.8Aikaan IoT management platform v3.25.0325-5-g2e9c59796 sends a newly generated password to users in plaintext via email ...
CVE-2025-43754MEDIUM5.3Username enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q4.0 through 2024.Q4....
CVE-2025-9311CRITICAL9.8A vulnerability was identified in itsourcecode Apartment Management System 1.0. Affected by this issue is some unknown f...
CVE-2025-9310HIGH7.5A vulnerability was determined in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3. Affected by this vuln...
CVE-2025-9309HIGH7A vulnerability was found in Tenda AC10 16.03.10.13. Affected is an unknown function of the file /etc_ro/shadow of the c...
CVE-2025-8402MEDIUM4.9Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to ...
CVE-2025-7969MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in markdown-it...
CVE-2025-6465MEDIUM4.3Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to sanitize file names...
CVE-2025-57765HIGH8.2WeGIA is a Web manager for charitable institutions. Prior to 3.4.7, a Reflected Cross-Site Scripting (XSS) vulnerability...
CVE-2025-57764HIGH8.2WeGIA is a Web manager for charitable institutions. Prior to 3.4.7, a Reflected Cross-Site Scripting (XSS) vulnerability...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now