2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-70314CRITICAL9.8webfsd 1.21 is vulnerable to a Buffer Overflow via a crafted request. This is due to the filename variable
CVE-2025-67433HIGH7.5A heap buffer overflow in the processRequest function of Open TFTP Server MultiThreaded v1.7 allows attackers to cause a...
CVE-2025-67432HIGH7.5A stack overflow in the ZBarcode_Encode function of Monkeybread Software MBS DynaPDF Plugin v21.3.1.1 allows attackers t...
CVE-2025-70981CRITICAL9.8CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds p...
CVE-2025-69807HIGH7.5p2r3 Bareiron commit: 8e4d4020d is vulnerable to Buffer Overflow, which allows unauthenticated remote attackers to cause...
CVE-2025-69806HIGH7.5p2r3 bareiron commit: 8e4d4020d contains an Out-of-bounds Read, which allows unauthenticated remote attackers to get rel...
CVE-2025-63421HIGH7.8An issue in filosoft Comerc.32 Commercial Invoicing v.16.0.0.3 allows a local attacker to execute arbitrary code via the...
CVE-2025-54519HIGH7.3A DLL hijacking vulnerability in Doc Nav could allow a local attacker to achieve privilege escalation, potentially resul...
CVE-2025-52533HIGH8.7Improper Access Control in an on-chip debug interface could allow a privileged attacker to enable a debug interface and ...
CVE-2025-61880HIGH8.8In Infoblox NIOS through 9.0.7, insecure deserialization can result in remote code execution.
CVE-2025-61879HIGH7.7In Infoblox NIOS through 9.0.7, a High-Privileged User Can Trigger an Arbitrary File Write via the Account Creation Mech...
CVE-2025-55210HIGH7.5FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to 17.0.5 and 16.0.17, F...
CVE-2025-54756HIGH8.6BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 use a default passwo...
CVE-2025-70886HIGH7.5An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the ...
CVE-2025-69752MEDIUM4.3An issue in the "My Details" user profile functionality of Ideagen Q-Pulse 7.1.0.32 allows an authenticated user to view...
CVE-2025-69634CRITICAL9Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges ...
CVE-2025-56647MEDIUM6.5npm @farmfe/core before 1.7.6 is Missing Origin Validation in WebSocket. The development (hot module reloading) server d...
CVE-2025-14014CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software H...
CVE-2025-13004MEDIUM6.3Authorization Bypass Through User-Controlled Key vulnerability in Farktor Software E-Commerce Services Inc. E-Commerce P...
CVE-2025-13002MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Farktor Sof...
CVE-2025-10969CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farktor Software E...
CVE-2025-15575MEDIUM5.3The firmware update functionality does not verify the authenticity of the supplied firmware update files. This allows at...
CVE-2025-15574MEDIUM6.5When connecting to the Solax Cloud MQTT server the username is the "registration number", which is the 10 character stri...
CVE-2025-15573CRITICAL9.4The affected devices do not validate the server certificate when connecting to the SolaX Cloud MQTTS server hosted in th...
CVE-2025-41117MEDIUM6.1Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the b...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now