2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-53515HIGH8.8A vulnerability exists in Advantech iView that allows for SQL injection and remote code execution through NetworkServle...
CVE-2025-53509HIGH7.1A vulnerability exists in Advantech iView that allows for argument injection in the NetworkServlet.restoreDatabase(). T...
CVE-2025-53475HIGH8.8A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution through Network...
CVE-2025-53471MEDIUM5.9Emerson ValveLink products receive input or data, but does not validate or incorrectly validates that the input has th...
CVE-2025-53397MEDIUM6.1A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site...
CVE-2025-52579CRITICAL9.4Emerson ValveLink Products store sensitive information in cleartext in memory. The sensitive memory might be saved to d...
CVE-2025-52577HIGH8.8A vulnerability exists in Advantech iView that could allow SQL injection and remote code execution through NetworkServl...
CVE-2025-52459HIGH7.1A vulnerability exists in Advantech iView that allows for argument injection in NetworkServlet.backupDatabase(). This i...
CVE-2025-50109HIGH8.5Emerson ValveLink Products store sensitive information in cleartext within a resource that might be accessible to anothe...
CVE-2025-48891HIGH7.6A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils.checkSQLInjection() fun...
CVE-2025-48496MEDIUM5.9Emerson ValveLink products use a fixed or controlled search path to find resources, but one or more locations in that ...
CVE-2025-46704MEDIUM5.3A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory tr...
CVE-2025-46358HIGH8.5Emerson ValveLink products do not use or incorrectly uses a protection mechanism that provides sufficient defense agai...
CVE-2025-41442MEDIUM5.4A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site...
CVE-2025-7419HIGH8.8A vulnerability was found in Tenda O3V2 1.0.0.12(3880). It has been classified as critical. This affects the function fr...
CVE-2025-7418HIGH8.8A vulnerability was found in Tenda O3V2 1.0.0.12(3880) and classified as critical. Affected by this issue is the functio...
CVE-2025-31267MEDIUM4.6An authentication issue was addressed with improved state management. This issue is fixed in App Store Connect 3.0. An a...
CVE-2025-1727HIGH8.1The protocol used for remote linking over RF for End-of-Train and Head-of-Train (also known as a FRED) relies on a BCH ...
CVE-2025-7417HIGH8.8A vulnerability has been found in Tenda O3V2 1.0.0.12(3880) and classified as critical. Affected by this vulnerability i...
CVE-2025-7416HIGH8.8A vulnerability, which was classified as critical, was found in Tenda O3V2 1.0.0.12(3880). Affected is the function from...
CVE-2025-6392MEDIUM4.4Brocade SANnav before Brocade SANnav 2.4.0a could log database passwords in clear text in audit logs when the daily data...
CVE-2025-53637HIGH8Meshtastic is an open source mesh networking solution. The main_matrix.yml GitHub Action is triggered by the pull_reques...
CVE-2025-24798MEDIUM6.5Meshtastic is an open source mesh networking solution. From 1.2.1 until 2.6.2, a packet sent to the routing module that ...
CVE-2025-7415HIGH8.8A vulnerability, which was classified as critical, has been found in Tenda O3V2 1.0.0.12(3880). This issue affects the f...
CVE-2025-7414HIGH8.8A vulnerability classified as critical was found in Tenda O3V2 1.0.0.12(3880). This vulnerability affects the function f...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now