2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-65568HIGH7.5A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1....
CVE-2025-65567HIGH7.5A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1....
CVE-2025-65565HIGH7.5A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1....
CVE-2025-65564HIGH7.5A denial-of-service vulnerability exists in the omec-upf (upf-epc-pfcpiface) in version upf-epc-pfcpiface:2.1.3-dev. Whe...
CVE-2025-65563HIGH7.5A denial-of-service vulnerability exists in the omec-project UPF (component upf-epc/pfcpiface) up to at least version up...
CVE-2025-65562HIGH7.5The free5GC UPF suffers from a lack of bounds checking on the SEID when processing PFCP Session Deletion Requests. An un...
CVE-2025-65561HIGH7.5An issue was discovered in function LocalNode.Sess in free5GC 4.1.0 allowing attackers to cause a denial of service or o...
CVE-2025-65559HIGH7.5An issue was discovered in Open5GS 2.7.5-49-g465e90f, when processing a PFCP Session Establishment Request (type=50), th...
CVE-2025-63387HIGH7.5Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to th...
CVE-2025-14885HIGH8.8A flaw has been found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file ...
CVE-2025-14738HIGH7.5Improper authentication vulnerability in TP-Link WA850RE (httpd modules) allows unauthenticated attackers to download th...
CVE-2025-14737HIGH8Command Injection vulnerability in TP-Link WA850RE (httpd modules) allows authenticated adjacent attacker to inject arbi...
CVE-2025-14896HIGH8.7due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an a...
CVE-2025-14884HIGH7.3A vulnerability was detected in D-Link DIR-605 202WWB03. Affected by this issue is some unknown functionality of the com...
CVE-2025-68278HIGH8.8Tina is a headless content management system. In tinacms prior to version 3.1.1, tinacms uses the gray-matter package in...
CVE-2025-64724HIGH7.3Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS is installed with wo...
CVE-2025-65011HIGH7.1In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) an unauthorised user can view configuration files by d...
CVE-2025-65010HIGH7.1WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) is vulnerable to Broken Access Control in initial configu...
CVE-2025-65009HIGH7.1In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) admin password is stored in configuration file as plai...
CVE-2025-65007HIGH8.7In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) due to lack of authentication in the configuration cha...
CVE-2025-64469HIGH8.5There is a stack-based buffer overflow vulnerability in NI LabVIEW in LVResFile::FindRsrcListEntry() when parsing a corr...
CVE-2025-64468HIGH8.5There is a use-after-free vulnerability in sentry!sentry_span_set_data() when parsing a corrupted VI file. This vulnera...
CVE-2025-64467HIGH8.5There is an out of bounds read vulnerability in NI LabVIEW in LVResFile::FindRsrcListEntry() when parsing a corrupted VI...
CVE-2025-64466HIGH8.5There is an out of bounds read vulnerability in NI LabVIEW in lvre!ExecPostedProcRecPost() when parsing a corrupted VI f...
CVE-2025-64465HIGH8.5There is an out of bounds read vulnerability in NI LabVIEW in lvre!DataSizeTDR() when parsing a corrupted VI file. This...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now