2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-8734Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn b...
CVE-2025-8733Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn b...
CVE-2025-5095CRITICAL9.8Burk Technology ARC Solo's password change mechanism can be utilized without proper authentication procedures, allowing...
CVE-2025-52914HIGH8.8A vulnerability in the Suite Applications Services component of Mitel MiCollab 10.0 through SP1 FP1 (10.0.1.101) could a...
CVE-2025-52913CRITICAL9.8A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP2 (9.8.2.12) could allo...
CVE-2025-50928MEDIUM4.8Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter ...
CVE-2025-50927MEDIUM6.3A reflected cross-site scripting (XSS) vulnerability in the List All FTP User Function in EHCP v20.04.1.b allows authent...
CVE-2025-8732LOW3.3A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the f...
CVE-2025-8393HIGH8.5A TLS vulnerability exists in the phone application used to manage a connected device. The phone application accepts se...
CVE-2025-8284CRITICAL9.8By default, the Packet Power Monitoring and Control Web Interface do not enforce authentication mechanisms. This vulner...
CVE-2025-53520HIGH8.8The affected product allows firmware updates to be downloaded from EG4's website, transferred via USB dongles, or insta...
CVE-2025-50468MEDIUM6.5OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function l...
CVE-2025-50467MEDIUM6.5OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function l...
CVE-2025-50466MEDIUM6.5OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function l...
CVE-2025-50465HIGH8.8OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function l...
CVE-2025-47872MEDIUM6.9The public-facing product registration endpoint server responds differently depending on whether the S/N is valid and u...
CVE-2025-46414CRITICAL9.2The affected product does not limit the number of attempts for inputting the correct PIN for a registered product, whic...
CVE-2025-8731CRITICAL9.8A vulnerability was identified in TRENDnet TI-G160i, TI-PG102i and TPL-430AP up to 20250724. This affects an unknown par...
CVE-2025-8356CRITICAL9.8In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized file...
CVE-2025-8355HIGH7.5In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker ...
CVE-2025-52586HIGH7.5The MOD3 command traffic between the monitoring application and the inverter is transmitted in plaintext without encryp...
CVE-2025-4576MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.133, and Liferay DXP 2025...
CVE-2025-8730CRITICAL9.8A vulnerability was found in Belkin F9K1009 and F9K1010 2.00.04/2.00.09 and classified as critical. Affected by this iss...
CVE-2025-36119HIGH8.8IBM i 7.3, 7.4, 7.5, and 7.6 is affected by an authenticated user obtaining elevated privileges with IBM Digital Certifi...
CVE-2025-36023MEDIUM6.5IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF005 and 24.0.1 through 24.0.1 IF002 could allow an authent...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now