2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-46093HIGH8.8LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execut...
CVE-2025-27212CRITICAL9.8An Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with a...
CVE-2025-27211HIGH7.5An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.10.4 and earlier) could allow a Command Injection by a mal...
CVE-2025-8528MEDIUM5.9A vulnerability classified as problematic has been found in Exrick xboot up to 3.3.4. Affected is an unknown function of...
CVE-2025-8527HIGH8.8A vulnerability was found in Exrick xboot up to 3.3.4. It has been rated as critical. This issue affects some unknown pr...
CVE-2025-7844LOW1Exporting a TPM based RSA key larger than 2048 bits from the TPM could overrun a stack buffer if the default `MAX_RSA_KE...
CVE-2025-54554MEDIUM5.3tiaudit in Tera Insights tiCrypt before 2025-07-17 allows unauthenticated REST API requests that reveal sensitive inform...
CVE-2025-4604MEDIUM6.1The vulnerable code can bypass the Captcha check in Liferay Portal 7.4.3.80 through 7.4.3.132, and Liferay DXP 2024.Q1.1...
CVE-2025-4599MEDIUM6.1The fragment preview functionality in Liferay Portal 7.4.3.61 through 7.4.3.132, and Liferay DXP 2024.Q4.1 through 2024....
CVE-2025-8526CRITICAL9.8A vulnerability was found in Exrick xboot up to 3.3.4. It has been declared as critical. This vulnerability affects the ...
CVE-2025-8525MEDIUM5.5A vulnerability was found in Exrick xboot up to 3.3.4. It has been classified as problematic. This affects an unknown pa...
CVE-2025-51726HIGH8.4CyberGhostVPNSetup.exe (Windows installer) is signed using the weak cryptographic hash algorithm SHA-1, which is vulnera...
CVE-2025-51387CRITICAL9.8The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to misconfigured Electron Fuses. Specifical...
CVE-2025-50754CRITICAL9.6Unisite CMS version 5.0 contains a stored Cross-Site Scripting (XSS) vulnerability in the "Report" functionality. A mali...
CVE-2025-50341CRITICAL9.8A Boolean-based SQL injection vulnerability was discovered in Axelor 5.2.4 via the _domain parameter. An attacker can ma...
CVE-2025-8524MEDIUM5.3A vulnerability was found in Boquan DotWallet App 2.15.2 on Android and classified as problematic. Affected by this issu...
CVE-2025-8523MEDIUM5.3A vulnerability has been found in RiderLike Fruit Crush-Brain App 1.0 on Android and classified as problematic. Affected...
CVE-2025-55014MEDIUM4.7The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X1...
CVE-2025-50340MEDIUM4.3An Insecure Direct Object Reference (IDOR) vulnerability was discovered in SOGo Webmail thru 5.6.0, allowing an authenti...
CVE-2025-8522MEDIUM5A vulnerability, which was classified as critical, was found in givanz Vvvebjs up to 2.0.4. Affected is an unknown funct...
CVE-2025-8521MEDIUM5.4A vulnerability, which was classified as problematic, has been found in givanz Vvveb up to 1.0.5. This issue affects som...
CVE-2025-53395HIGH7.7Paramount Macrium Reflect through 2025-06-26 allows local attackers to execute arbitrary code with administrator privile...
CVE-2025-53394HIGH7.7Paramount Macrium Reflect through 2025-06-26 allows attackers to execute arbitrary code with administrator privileges vi...
CVE-2025-52239CRITICAL9.8An arbitrary file upload vulnerability in ZKEACMS v4.1 allows attackers to execute arbitrary code via a crafted file.
CVE-2025-38741HIGH7.5Dell Enterprise SONiC OS, version 4.5.0, contains a cryptographic key vulnerability in SSH. An unauthenticated remote at...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now