2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-59542CRITICAL9Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerab...
CVE-2025-55289CRITICAL9Chamilo is a learning management system. Prior to version 1.11.34, there is a stored XSS vulnerability in Chamilo LMS (V...
CVE-2025-70948CRITICAL9.3A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain ...
CVE-2025-55208CRITICAL9Chamilo is a learning management system. Versions prior to 1.11.34 have a Stored XSS through insecure file uploads in `S...
CVE-2025-29165CRITICAL9.8An issue in D-Link DIR-1253 MESH V1.6.1684 allows an attacker to escalate privileges via the etc/shadow.sample component
CVE-2025-70233CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetEnableWizard.
CVE-2025-70232CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetMACFilter.
CVE-2025-70231CRITICAL9.8D-Link DIR-513 version 1.10 contains a critical-level vulnerability. When processing POST requests related to verificati...
CVE-2025-70230CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDDNS.
CVE-2025-70229CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSchedule.
CVE-2025-13476CRITICAL9.8Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 uses a static and predictable TLS ClientH...
CVE-2025-69338CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in don-themes Riode C...
CVE-2025-68555CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Nutrie nutrie allows Upload a Web Shell to a...
CVE-2025-68554CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Keenarch keenarch allows Using Malicious Fil...
CVE-2025-68553CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Lendiz lendiz allows Upload a Web Shell to a...
CVE-2025-54001CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeREX Classter classter allows Object Injection.This issue affects...
CVE-2025-40931CRITICAL9.1Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id. Apache::Session::Generate::MD...
CVE-2025-40926CRITICAL9.8Plack::Middleware::Session::Simple versions before 0.05 for Perl generates session ids insecurely. The default session ...
CVE-2025-70222CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin,goform/getAuth...
CVE-2025-66024CRITICAL9The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions starting with 9....
CVE-2025-70225CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curtime parameter to the goform/formEasySetupWWConfi...
CVE-2025-70221CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin.
CVE-2025-46108CRITICAL9.8D-link Dir-513 A1FW110 is vulnerable to Buffer Overflow in the function formTcpipSetup.
CVE-2025-70219CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the goform/formDeviceReboot.
CVE-2025-70226CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formEasySetupWizard.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now