2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-55137HIGH7.4LinkJoin through 882f196 mishandles lacks type checking in password reset.
CVE-2025-54397MEDIUM4.3Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 inserts Sensitive Information Into Se...
CVE-2025-54396MEDIUM5.4Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows SQL Injection. Authenticated u...
CVE-2025-54395MEDIUM6.1Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication configu...
CVE-2025-54394MEDIUM5.3Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protected Credenti...
CVE-2025-54393MEDIUM5.4Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows Static Code Injection. Authent...
CVE-2025-54392MEDIUM6.1Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error d...
CVE-2025-34152CRITICAL9.4An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model ...
CVE-2025-34151CRITICAL9.4A command injection vulnerability exists in the 'passwd' parameter of the PPPoE setup process on the Shenzhen Aitemi M30...
CVE-2025-34150CRITICAL9.4The PPPoE configuration interface of the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) is vulnerable to comm...
CVE-2025-34149CRITICAL9.4A command injection vulnerability affects the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) during WPA2 conf...
CVE-2025-34148CRITICAL9.4An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model ...
CVE-2025-24000HIGH8.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Saad Iqbal Post SMTP post-smtp allows Authenti...
CVE-2025-7054MEDIUM6.5Cloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_...
CVE-2025-55136MEDIUM5.7ERC (aka Emotion Recognition in Conversation) through 0.3 has insecure deserialization via a serialized object because j...
CVE-2025-55135MEDIUM6.4In Agora Foundation Agora fall23-Alpha1 before 690ce56, there is XSS via a profile picture to server/controller/userCont...
CVE-2025-55134MEDIUM6.4In Agora Foundation Agora fall23-Alpha1 before b087490, there is XSS via tag in client/agora/public/js/editorManager.js.
CVE-2025-55133MEDIUM6.4In Agora Foundation Agora fall23-Alpha1 before b087490, there is XSS via topicName in client/agora/public/js/editorManag...
CVE-2025-47907HIGH7Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method ...
CVE-2025-44779MEDIUM6.6An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/...
CVE-2025-50952MEDIUM6.5openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c.
CVE-2025-47188MEDIUM6.5A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and th...
CVE-2025-8533MEDIUM6.9A vulnerability was identified in the XPC services of Fantastical. The services failed to implement proper client author...
CVE-2025-35970HIGH8.7On multiple products of SEIKO EPSON and FUJIFILM Corporation, the initial administrator password is easy to guess from t...
CVE-2025-29866HIGH8.8: External Control of File Name or Path vulnerability in TAGFREE X-Free Uploader XFU allows : Parameter Injection.This i...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now