2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-27213MEDIUM4.9An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect devices to en...
CVE-2025-24285CRITICAL9.8Multiple Improper Input Validation vulnerabilities in UniFi Connect EV Station Lite may allow a Command Injection by a m...
CVE-2025-9264MEDIUM5.4A vulnerability was found in Xuxueli xxl-job up to 3.1.1. Affected by this issue is the function remove of the file /src...
CVE-2025-9263MEDIUM4.3A vulnerability has been found in Xuxueli xxl-job up to 3.1.1. Affected by this vulnerability is the function getJobsByG...
CVE-2025-9262HIGH8.1A flaw has been found in wong2 mcp-cli 1.13.0. Affected is the function redirectToAuthorization of the file /src/oauth/p...
CVE-2025-9253HIGH8.8A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0....
CVE-2025-9288CRITICAL9.1Improper Input Validation vulnerability in sha.js allows Input Data Manipulation.This issue affects sha.js: through 2.4....
CVE-2025-9287CRITICAL9.1Improper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: th...
CVE-2025-9252HIGH8.8A weakness has been identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.0...
CVE-2025-9251HIGH8.8A security flaw has been discovered in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/...
CVE-2025-9250HIGH8.8A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.0...
CVE-2025-57749MEDIUM6.5n8n is a workflow automation platform. Before 1.106.0, a symlink traversal vulnerability was discovered in the Read/Writ...
CVE-2025-9249HIGH8.8A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.0...
CVE-2025-9248HIGH8.8A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002...
CVE-2025-9247HIGH8.8A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.0...
CVE-2025-9246HIGH8.8A flaw has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1...
CVE-2025-9245HIGH8.8A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04....
CVE-2025-9244HIGH8.8A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0....
CVE-2025-9241HIGH7.5A weakness has been identified in elunez eladmin up to 2.7. This affects the function exportUser. This manipulation caus...
CVE-2025-5115HIGH7.5In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the ...
CVE-2025-54988HIGH8.4Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms al...
CVE-2025-50902HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in old-peanut Open-Shop (aka old-peanut/wechat_applet__open_source) thru...
CVE-2025-43757MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025...
CVE-2025-9240MEDIUM4.3A security flaw has been discovered in elunez eladmin up to 2.7. Affected by this issue is some unknown functionality of...
CVE-2025-43746MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now