2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-45769MEDIUM6.5php-jwt v6.11.0 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key leng...
CVE-2025-37112MEDIUM6A vulnerability was discovered in the storage policy for certain sets of encryption keys in the HPE Telco Network Functi...
CVE-2025-37111MEDIUM6A vulnerability was discovered in the storage policy for certain sets of authentication keys in the HPE Telco Network Fu...
CVE-2025-37110MEDIUM6A vulnerability was discovered in the storage policy for certain sets of sensitive credential information in the HPE Tel...
CVE-2025-37109LOW3.5Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product
CVE-2025-37108LOW3.5Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product
CVE-2025-26064HIGH7.3A cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arb...
CVE-2025-26063CRITICAL9.8An issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to execute arbitrary code via in...
CVE-2025-26062CRITICAL9.8An access control issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to access the rou...
CVE-2025-8426CRITICAL9.4Marvell QConvergeConsole compressConfigFiles Directory Traversal Information Disclosure and Denial-of-Service Vulnerabil...
CVE-2025-54834MEDIUM6.9OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/...
CVE-2025-54833HIGH7.5OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows attackers to bypass account-lockout and CAPTCHA protec...
CVE-2025-54832MEDIUM5.3OPEXUS FOIAXpress Public Access Link (PAL), version v11.1.0, allows an authenticated user to add entries to the list of ...
CVE-2025-51503HIGH7.6A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2.0 allows attackers to inject malicious scripts int...
CVE-2025-51385LOW3.5D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the yyxz_dlink_asp function via the id parameter.
CVE-2025-51384LOW3.5D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_net_asp function via the remot_ip parameter.
CVE-2025-51383LOW3.5D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_road_asp function via the host_ip parameter.
CVE-2025-50866MEDIUM6.1CloudClassroom-PHP-Project 1.0 contains a reflected Cross-site Scripting (XSS) vulnerability in the email parameter of t...
CVE-2025-8409CRITICAL9.8A vulnerability has been found in code-projects Vehicle Management 1.0 and classified as critical. Affected by this vuln...
CVE-2025-52203HIGH7.6A stored cross-site scripting (XSS) vulnerability exists in DevaslanPHP project-management v1.2.4. The vulnerability res...
CVE-2025-50867MEDIUM6.5A SQL Injection vulnerability exists in the takeassessment2.php endpoint of the CloudClassroom-PHP-Project 1.0, where th...
CVE-2025-50850HIGH8.6An issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such a...
CVE-2025-50848MEDIUM6.1A file upload vulnerability was discovered in CS Cart 4.18.3, allows attackers to execute arbitrary code. CS Cart 4.18.3...
CVE-2025-50847MEDIUM6.5Cross Site Request Forgery (CSRF) vulnerability in CS Cart 4.18.3, allows attackers to add products to a user's comparis...
CVE-2025-46809MEDIUM6.9A Plaintext Storage of a Password vulnerability in SUSE exposes the credentials for the HTTP proxy in the log files. Thi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now