2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-34128HIGH8.6A buffer overflow vulnerability exists in the X360 VideoPlayer ActiveX control (VideoPlayer.ocx) version 2.6 when handli...
CVE-2025-34127CRITICAL9.3A stack-based buffer overflow exists in Achat v0.150 in its default configuration. By sending a specially crafted messag...
CVE-2025-34126HIGH8.7A path traversal vulnerability exists in RIPS Scanner version 0.54. The vulnerability allows remote attackers to read ar...
CVE-2025-34125CRITICAL9.3An unauthenticated command injection vulnerability exists in the cookie handling process of the lighttpd web server on D...
CVE-2025-34124HIGH8.4A buffer overflow vulnerability exists in Heroes of Might and Magic III Complete 4.0.0.0, HD Mod 3.808 build 9, and Demo...
CVE-2025-34123HIGH8.4A stack-based buffer overflow vulnerability exists in VideoCharge Studio 2.12.3.685 when processing a specially crafted ...
CVE-2025-34121CRITICAL9.3An unauthenticated arbitrary file upload vulnerability exists in Idera Up.Time Monitoring Station versions up to and inc...
CVE-2025-34120HIGH8.7An unauthenticated file download vulnerability exists in LimeSurvey versions from 2.0+ up to and including 2.06+ Build 1...
CVE-2025-34119HIGH8.8A remote file disclosure vulnerability exists in EasyCafe Server 2.2.14, exploitable by unauthenticated remote attackers...
CVE-2025-34118HIGH8.7A path traversal vulnerability exists in Linknat VOS Manager versions prior to 2.1.9.07, including VOS2009 and early VOS...
CVE-2025-34117CRITICAL9.3A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior t...
CVE-2025-6983MEDIUM5.1A Clickjacking vulnerability in TP-Link Archer C1200 web management page allows an attacker to trick users into perfor...
CVE-2025-6982MEDIUM6.9Use of Hard-coded Credentials in TP-Link Archer C50 V3( <= 180703)/V4( <= 250117 )/V5( <= 200407 ), and C20 ...
CVE-2025-53908HIGH8.3RomM is a self-hosted rom manager and player. Versions prior to 3.10.3 and 4.0.0-beta.3 have an authenticated path trave...
CVE-2025-40777HIGH7.5If a `named` caching resolver is configured with `serve-stale-enable` `yes`, and with `stale-answer-client-timeout` set ...
CVE-2025-37107CRITICAL9.8An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.
CVE-2025-37106CRITICAL9.8An authentication bypass and disclosure of information vulnerability exists in HPE AutoPass License Server (APLS) prior ...
CVE-2025-37105CRITICAL9.8An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.
CVE-2025-36097HIGH7.5IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 are vulnerable t...
CVE-2025-53904LOW1.3The Scratch Channel is a news website that is under development as of time of this writing. The file `/api/admin.js` con...
CVE-2025-20337CRITICAL10A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to exec...
CVE-2025-20288MEDIUM5.3A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticate...
CVE-2025-20285MEDIUM4.1A vulnerability in the IP Access Restriction feature of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote...
CVE-2025-20284HIGH7.2A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execut...
CVE-2025-20283HIGH7.2A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execut...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now