2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-26476MEDIUM5.5Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0, contain a Use of Hard-coded Cryptographic Key vulnerabi...
CVE-2025-21120MEDIUM6.5Dell Avamar, versions prior to 19.10 SP1 with patch 338904, contains a Trusting HTTP Permission Methods on the Server-Si...
CVE-2025-8520MEDIUM4.7A vulnerability classified as critical was found in givanz Vvveb up to 1.0.5. This vulnerability affects unknown code of...
CVE-2025-8519LOW2.7A vulnerability classified as problematic has been found in givanz Vvveb up to 1.0.5. This affects an unknown part of th...
CVE-2025-51390CRITICAL9.8TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a command injection vulnerability via the pin parameter...
CVE-2025-46206MEDIUM6.5An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion...
CVE-2025-34147CRITICAL9.4An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model ...
CVE-2025-8518HIGH7.2A vulnerability was found in givanz Vvveb 1.0.5. It has been rated as critical. Affected by this issue is the function S...
CVE-2025-51535CRITICAL9.1Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a SQL injection vulnerability.
CVE-2025-51534HIGH8.1A cross-site scripting (XSS) vulnerability in Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 allows attackers ...
CVE-2025-50422LOW2.9Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face == NULL" assertion failure for _cairo_f...
CVE-2025-50420MEDIUM6.5An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via ...
CVE-2025-44963HIGH8.1RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded ...
CVE-2025-44962MEDIUM4.3RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows ../ directory traversal to read files.
CVE-2025-44961HIGH8.8In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided b...
CVE-2025-44960HIGH8.8RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.
CVE-2025-44958HIGH7.5RUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format.
CVE-2025-44957HIGH8.8Ruckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP hea...
CVE-2025-44954CRITICAL9.8RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.
CVE-2025-8517MEDIUM6.3A vulnerability was detected in givanz Vvveb 1.0.6.1. Impacted is an unknown function. The manipulation results in sessi...
CVE-2025-8516MEDIUM5.5A security vulnerability has been detected in Kingdee Cloud-Starry-Sky Enterprise Edition up to 8.2. This issue affects ...
CVE-2025-5988MEDIUM5.3A flaw was found in the Ansible aap-gateway. Cross-site request forgery (CSRF) origin checking is not done on requests f...
CVE-2025-44955HIGH8.8RUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root access vis a weak, hardcoded password.
CVE-2025-38739MEDIUM5.3Dell Digital Delivery, versions prior to 5.6.1.0, contains an Insufficiently Protected Credentials vulnerability. A remo...
CVE-2025-51536CRITICAL9.8Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded Administrator password.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now