2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-70223CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAdvNetwork.
CVE-2025-70220CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAutoDetecWAN_wizard4...
CVE-2025-70218CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via POST to the goform/formAdvFirewall component.
CVE-2025-69969CRITICAL9.6A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Po...
CVE-2025-66944CRITICAL9.8SQL Injection vulnerability in vran-dev databaseir v.1.0.7 and before allows a remote attacker to execute arbitrary code...
CVE-2025-66678CRITICAL9.8An issue in the HwRwDrv.sys component of Nil Hardware Editor Hardware Read & Write Utility v1.25.11.26 and earlier allow...
CVE-2025-59786CRITICAL9.82N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to ...
CVE-2025-70240CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard51.
CVE-2025-70239CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard55.
CVE-2025-70234CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetQoS.
CVE-2025-70241CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWANType_Wizard5.
CVE-2025-70237CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetPortTr.
CVE-2025-70236CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDomainFilter.
CVE-2025-66945CRITICAL9.1A path traversal vulnerability exists in the ZIP extraction API of Zdir Pro 4.x. When a crafted ZIP archive is processed...
CVE-2025-14923CRITICAL9.8IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could prov...
CVE-2025-70821CRITICAL9.8renren-secuity before v5.5.0 is vulnerable to SQL Injection in the BaseServiceImpl.java component
CVE-2025-57622CRITICAL9.8An issue in Step-Video-T2V allows a remote attacker to execute arbitrary code via the /vae-api , /caption-api , feature ...
CVE-2025-59059CRITICAL9.8Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users ...
CVE-2025-48609CRITICAL9.1In multiple functions of MmsProvider.java, there is a possible way to arbitrarily delete files which affect telephony, S...
CVE-2025-52998CRITICAL9.8Chamilo is a learning management system. Prior to version 1.11.30, in the application, deserialization of data is perfor...
CVE-2025-50199CRITICAL9.1Chamilo is a learning management system. Prior to version 1.11.30, there is a blind SSRF vulnerability in /index.php via...
CVE-2025-50192CRITICAL9.8Chamilo is a learning management system. Prior to version 1.11.30, there is a time-based SQL Injection in found in /main...
CVE-2025-50190CRITICAL9.8Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via the GET ope...
CVE-2025-50187CRITICAL9.8Chamilo is a learning management system. Prior to version 1.11.28, parameter from SOAP request is evaluated without filt...
CVE-2025-14532CRITICAL9.8DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now