2025 CVE Vulnerabilities

45,137 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-41770HIGH7.5An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an rem...
CVE-2025-54512HIGH7A DLL hijacking vulnerability within the AMD Ryzen Master installation could allow a local user-privileged attacker to e...
CVE-2025-0046HIGH7Incorrect directory permissions could allow a local user to escalate their privileges, potentially resulting in arbitrar...
CVE-2025-8087HIGH7A DLL hijacking vulnerability in AMD Power Design Manager could allow a malicious local attacker to escalate privileges ...
CVE-2025-31936HIGH7Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) ...
CVE-2025-30241HIGH8.6Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input pro...
CVE-2025-30239HIGH8.5In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive co...
CVE-2025-30238HIGH8.6In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to e...
CVE-2025-30237HIGH8.7The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not c...
CVE-2025-15683HIGH8.8TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial-of-service vulnerabilities in its web server. An ...
CVE-2025-15682HIGH8.7TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exhaustion vulnerability in its web server. An unauth...
CVE-2025-71412HIGH7.1Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion...
CVE-2025-71409HIGH7.1Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages ...
CVE-2025-63235HIGH7.5In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CON...
CVE-2025-49506HIGH7.5APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or p...
CVE-2025-15028HIGH7.2The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is ...
CVE-2025-63822HIGH8.1SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate...
CVE-2025-70962HIGH7.5Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials ...
CVE-2025-15629HIGH7.5A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communicati...
CVE-2025-15628HIGH7.5Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between contr...
CVE-2025-15627HIGH7.5A cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys to...
CVE-2025-15672HIGH8.1The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserializa...
CVE-2025-71400HIGH7.1better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey delet...
CVE-2025-71399HIGH8.8Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalize...
CVE-2025-71403HIGH7.1better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now