2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-53012HIGH7.5MaterialX is an open standard for the exchange of rich material and look-development content across applications and ren...
CVE-2025-53011HIGH7.5MaterialX is an open standard for the exchange of rich material and look-development content across applications and ren...
CVE-2025-53010HIGH7.5MaterialX is an open standard for the exchange of rich material and look-development content across applications and ren...
CVE-2025-53009HIGH7.5MaterialX is an open standard for the exchange of rich material and look-development content across applications and ren...
CVE-2025-50870CRITICAL9.8Institute-of-Current-Students 1.0 is vulnerable to Incorrect Access Control in the mydetailsstudent.php endpoint. The my...
CVE-2025-50869MEDIUM6.1A stored Cross-Site Scripting (XSS) vulnerability exists in the qureydetails.php page of Institute-of-Current-Students 1...
CVE-2025-50868MEDIUM6.5A SQL Injection vulnerability exists in the takeassessment2.php file of CloudClassroom-PHP-Project 1.0. The Q4 POST para...
CVE-2025-49832MEDIUM6.5Asterisk is an open source private branch exchange and telephony toolkit. In versions up to and including 18.26.2, betwe...
CVE-2025-33118MEDIUM5.4IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 12 is vulnerable to stored cross-site scripting. This vulnerability allows...
CVE-2025-2824HIGH7.4IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, 9.0.0.1, and 9.5.0 could allow a remote attacker to condu...
CVE-2025-51504HIGH7.6Microweber CMS 2.0 is vulnerable to Cross Site Scripting (XSS)in the /projects/profile, homepage endpoint via the last n...
CVE-2025-51502MEDIUM6.1Reflected Cross-Site Scripting (XSS) in Microweber CMS 2.0 via the layout parameter on the /admin/page/create page allow...
CVE-2025-51501MEDIUM6.1Reflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS...
CVE-2025-48074MEDIUM5.5OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2025-45778MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in The Language Sloth Web Application v1.0 allows attackers to execute...
CVE-2025-45150CRITICAL9.8Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view and download sensitive...
CVE-2025-52390CRITICAL9.1Saurus CMS Community Edition since commit d886e5b0 (2010-04-23) is vulnerable to a SQL Injection vulnerability in the `p...
CVE-2025-52361HIGH7.8Insecure permissions in the script /etc/init.d/lighttpd in AK-Nord USB-Server-LXL Firmware v0.0.16 Build 2023-03-13 allo...
CVE-2025-52327HIGH7.8SQL Injection vulnerability in Restaurant Order System 1.0 allows a local attacker to obtain sensitive information via t...
CVE-2025-50472CRITICAL9.8The modelscope/ms-swift library thru 2.6.1 is vulnerable to arbitrary code execution through deserialization of untruste...
CVE-2025-50460CRITICAL9.8A remote code execution (RCE) vulnerability exists in the ms-swift project version 3.3.0 due to unsafe deserialization i...
CVE-2025-44139HIGH7.2Emlog Pro V2.5.7 is vulnerable to Unrestricted Upload of File with Dangerous Type via /emlog/admin/plugin.php?action=upl...
CVE-2025-45767HIGH7jose v6.0.10 was discovered to contain weak encryption. NOTE: this is disputed by a third party because the claim of "do...
CVE-2025-46018MEDIUM5.4CSC Pay Mobile App 2.19.4 (fixed in version 2.20.0) contains a vulnerability allowing users to bypass payment authorizat...
CVE-2025-41376MEDIUM5.3CRLF Injection vulnerability in Limesurvey v2.65.1+170522.  This vulnerability could allow a remote attacker to inject a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now