2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-46852MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-46849MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-28041HIGH8.6Incorrect access control in the doFilter function of itranswarp up to 2.19 allows attackers to access sensitive componen...
CVE-2025-20345MEDIUM4.9A vulnerability in the debug logging function of Cisco Duo Authentication Proxy could allow an authenticated, high-privi...
CVE-2025-20269MEDIUM6.5A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri...
CVE-2025-20131MEDIUM4.9A vulnerability in the GUI of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with ad...
CVE-2025-9233MEDIUM5.4A security vulnerability has been detected in Scada-LTS up to 2.7.8.1. Impacted is an unknown function of the file view_...
CVE-2025-55751MEDIUM5.1OnboardLite is the result of the Influx Initiative, our vision for an improved student organization lifecycle at the Uni...
CVE-2025-55732HIGH7.5Frappe is a full-stack web application framework. Prior to 15.74.2 and 14.96.15, an attacker could implement SQL injecti...
CVE-2025-55731HIGH8.8Frappe is a full-stack web application framework. A carefully crafted request could extract data that the user would nor...
CVE-2025-55498HIGH7.5Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the time parameter in the fromSetSysTime fu...
CVE-2025-55482HIGH7.5Tenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the formSetCfm function.
CVE-2025-51991HIGH8.8XWiki through version 17.3.0 is vulnerable to Server-Side Template Injection (SSTI) in the Administration interface, spe...
CVE-2025-51990MEDIUM4.8XWiki through version 17.3.0 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities in the Administra...
CVE-2025-50864MEDIUM6.5An Origin Validation Error in the elysia-cors library thru 1.3.0 allows attackers to bypass Cross-Origin Resource Sharin...
CVE-2025-43748MEDIUM6.8Insufficient CSRF protection for omni-administrator users in Liferay Portal 7.0.0 through 7.4.3.119, and Liferay DXP 202...
CVE-2025-36114HIGH7.5IBM QRadar SOAR Plugin App 1.0.0 through 5.6.0 could allow a remote attacker to traverse directories on the system. An a...
CVE-2025-1142MEDIUM5.4IBM Edge Application Manager 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated at...
CVE-2025-1139MEDIUM4.4IBM Edge Application Manager 4.5 could allow a local user to read or modify resources that they should not have authoriz...
CVE-2025-9074CRITICAL9.3A vulnerability was identified in Docker Desktop that allows local running Linux containers to access the Docker Engine ...
CVE-2025-8449MEDIUM4.1CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service when an authenticat...
CVE-2025-8448LOW1CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause unauthorized a...
CVE-2025-55503HIGH7.3Tenda AC6 V15.03.06.23_multi has a stack overflow vulnerability via the deviceName parameter in the saveParentControlInf...
CVE-2025-55499MEDIUM6.5Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the ntpServer parameter in the fromSetSysTi...
CVE-2025-55483HIGH7.5Tenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the function formSetMacFilterCfg via the parameters mac...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now