2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-55032MEDIUM6.1Focus for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the conten...
CVE-2025-55031CRITICAL9.8Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An att...
CVE-2025-55030MEDIUM6.1Firefox for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the cont...
CVE-2025-55029HIGH7.5Malicious scripts could bypass the popup blocker to spam new tabs, potentially resulting in denial of service attacks. T...
CVE-2025-55028MEDIUM6.5Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and all...
CVE-2025-54145CRITICAL9.1The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that lev...
CVE-2025-54144MEDIUM5.4The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitra...
CVE-2025-54143CRITICAL9.8Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictio...
CVE-2025-9165LOW2.5A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCC...
CVE-2025-9157MEDIUM5.3A vulnerability was determined in appneta tcpreplay up to 4.5.2-beta2. The impacted element is the function untrunc_pack...
CVE-2025-9156CRITICAL9.8A vulnerability was found in itsourcecode Sports Management System 1.0. The affected element is an unknown function of t...
CVE-2025-9155CRITICAL9.8A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Impacted is an unknown func...
CVE-2025-55740MEDIUM6.5nginx-defender is a high-performance, enterprise-grade Web Application Firewall (WAF) and threat detection system engine...
CVE-2025-55737MEDIUM6.5flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when deleting a comment, there's no validation of the ow...
CVE-2025-52337MEDIUM6.5An authenticated arbitrary file upload vulnerability in the Content Explorer feature of LogicData eCommerce Framework v5...
CVE-2025-51543CRITICAL9.8An issue was discovered in Cicool builder 3.4.4 allowing attackers to reset the administrator's password via the /admini...
CVE-2025-50926MEDIUM6.5Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter ...
CVE-2025-43744MEDIUM5.4A stored DOM-based Cross-Site Scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2...
CVE-2025-43743MEDIUM4.3Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q...
CVE-2025-2988MEDIUM6.5IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7, 6.2.0.0 through 6.2.0.4, and 6.2.1.0 ...
CVE-2025-9154CRITICAL9.8A flaw has been found in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown proc...
CVE-2025-9153HIGH8.8A vulnerability was detected in itsourcecode Online Tour and Travel Management System 1.0. This vulnerability affects un...
CVE-2025-55736MEDIUM6.5flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving...
CVE-2025-55735MEDIUM5.4flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when creating a post, there's no validation of the conte...
CVE-2025-55734MEDIUM6.5flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, the code checks if the userRole is "admin" only when vis...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now