2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-54927MEDIUM4.9CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could c...
CVE-2025-54926HIGH7.2CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could c...
CVE-2025-54925HIGH7.5CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data ...
CVE-2025-54924HIGH7.5CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data ...
CVE-2025-54923HIGH8.7CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution and compromise of...
CVE-2025-50503HIGH8.8A vulnerability in the password reset workflow of the Touch Lebanon Mobile App 2.20.2 allows an attacker to bypass the O...
CVE-2025-32010CRITICAL9.8A stack-based buffer overflow vulnerability exists in the Cloud API functionality of Tenda AC6 V5.0 V02.03.01.110. A spe...
CVE-2025-31355CRITICAL9.8A firmware update vulnerability exists in the Firmware Signature Validation functionality of Tenda AC6 V5.0 V02.03.01.11...
CVE-2025-30256HIGH7.5A denial of service vulnerability exists in the HTTP Header Parsing functionality of Tenda AC6 V5.0 V02.03.01.110. A spe...
CVE-2025-27129CRITICAL9.8An authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110. ...
CVE-2025-24496HIGH7.5An information disclosure vulnerability exists in the /goform/getproductInfo functionality of Tenda AC6 V5.0 V02.03.01.1...
CVE-2025-24322CRITICAL9.8An unsafe default authentication vulnerability exists in the Initial Setup Authentication functionality of Tenda AC6 V5....
CVE-2025-8453HIGH8.4CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation and arbitrary code exe...
CVE-2025-54175MEDIUM6.1QuickCMS.EXT is vulnerable to Reflected XSS in sFileName parameter in thumbnail viewer functionality.  An attacker can c...
CVE-2025-54174MEDIUM4.3QuickCMS is vulnerable to Cross-Site Request Forgery in article creation functionality. Malicious attacker can craft spe...
CVE-2025-54172MEDIUM4.8QuickCMS is vulnerable to Stored XSS in sTitle parameter in page editor functionality. Malicious attacker with admin pri...
CVE-2025-4877MEDIUM4.5There's a vulnerability in the libssh package where when a libssh consumer passes in an unexpectedly large input buffer ...
CVE-2025-4437MEDIUM5.7There's a vulnerability in the CRI-O application where when container is launched with securityContext.runAsUser specify...
CVE-2025-43750MEDIUM6.5Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q...
CVE-2025-43749MEDIUM5.3Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q...
CVE-2025-8102MEDIUM5.4The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2025-7777MEDIUM6.5The mirror-registry doesn't properly sanitize the host header HTTP header in HTTP request received, allowing an attacker...
CVE-2025-43742MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025...
CVE-2025-43741MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025...
CVE-2025-9173Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn b...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now