2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-65009HIGH7.1In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) admin password is stored in configuration file as plai...
CVE-2025-65007HIGH8.7In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) due to lack of authentication in the configuration cha...
CVE-2025-64469HIGH8.5There is a stack-based buffer overflow vulnerability in NI LabVIEW in LVResFile::FindRsrcListEntry() when parsing a corr...
CVE-2025-64468HIGH8.5There is a use-after-free vulnerability in sentry!sentry_span_set_data() when parsing a corrupted VI file. This vulnera...
CVE-2025-64467HIGH8.5There is an out of bounds read vulnerability in NI LabVIEW in LVResFile::FindRsrcListEntry() when parsing a corrupted VI...
CVE-2025-64466HIGH8.5There is an out of bounds read vulnerability in NI LabVIEW in lvre!ExecPostedProcRecPost() when parsing a corrupted VI f...
CVE-2025-64465HIGH8.5There is an out of bounds read vulnerability in NI LabVIEW in lvre!DataSizeTDR() when parsing a corrupted VI file. This...
CVE-2025-64464HIGH8.5There is an out of bounds read vulnerability in NI LabVIEW in lvre!VisaWriteFromFile() when parsing a corrupted VI file....
CVE-2025-64463HIGH8.5There is an out of bounds read vulnerability in NI LabVIEW in LVResource::DetachResource() when parsing a corrupted VI f...
CVE-2025-64462HIGH8.5There is an out of bounds read vulnerability in NI LabVIEW in LVResFile::RGetMemFileHandle() when parsing a corrupted VI...
CVE-2025-64461HIGH8.5There is an out of bounds write vulnerability in NI LabVIEW in mgocre_SH_25_3!RevBL() when parsing a corrupted VI file. ...
CVE-2025-63757HIGH7.5Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0.
CVE-2025-1031HIGH7.5Authorization Bypass Through User-Controlled Key vulnerability in Utarit Informatics Services Inc. SoliClub allows Funct...
CVE-2025-1030HIGH7.5Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Utarit Informatics Services Inc. Soli...
CVE-2025-1029HIGH7.5Use of Hard-coded Credentials vulnerability in Utarit Information Services Inc. SoliClub allows Read Sensitive Constants...
CVE-2025-14861HIGH8.8Memory safety bugs present in Firefox 146. Some of these bugs showed evidence of memory corruption and we presume that w...
CVE-2025-40898HIGH8.1A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validatio...
CVE-2025-40892HIGH8.9A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an...
CVE-2025-14437HIGH7.5The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, ...
CVE-2025-14364HIGH8.8The Demo Importer Plus plugin for WordPress is vulnerable to unauthorized modification of data, loss of data, and privil...
CVE-2025-13641HIGH8.8The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclu...
CVE-2025-14874HIGH7.5A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header t...
CVE-2025-6326HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-6324HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MatrixAddons Easy ...
CVE-2025-66119HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Hostel hostel ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now