2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-70229 | CRITICAL | 9.8 | 0.6% | Mar 5, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSchedule. |
| CVE-2025-13476 | CRITICAL | 9.8 | 0.3% | Mar 5, 2026 | Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 uses a static and predictable TLS ClientH... |
| CVE-2025-69338 | CRITICAL | 9.3 | 0.4% | Mar 5, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in don-themes Riode C... |
| CVE-2025-68555 | CRITICAL | 9.9 | 0.4% | Mar 5, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Nutrie nutrie allows Upload a Web Shell to a... |
| CVE-2025-68554 | CRITICAL | 9.9 | 0.4% | Mar 5, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Keenarch keenarch allows Using Malicious Fil... |
| CVE-2025-68553 | CRITICAL | 9.9 | 0.4% | Mar 5, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Lendiz lendiz allows Upload a Web Shell to a... |
| CVE-2025-54001 | CRITICAL | 9.8 | 0.5% | Mar 5, 2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Classter classter allows Object Injection.This issue affects... |
| CVE-2025-40931 | CRITICAL | 9.1 | 0.6% | Mar 5, 2026 | Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id. Apache::Session::Generate::MD... |
| CVE-2025-40926 | CRITICAL | 9.8 | 0.4% | Mar 5, 2026 | Plack::Middleware::Session::Simple versions before 0.05 for Perl generates session ids insecurely. The default session ... |
| CVE-2025-70222 | CRITICAL | 9.8 | 0.5% | Mar 4, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin,goform/getAuth... |
| CVE-2025-66024 | CRITICAL | 9 | 0.4% | Mar 4, 2026 | The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions starting with 9.... |
| CVE-2025-70225 | CRITICAL | 9.8 | 0.5% | Mar 4, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curtime parameter to the goform/formEasySetupWWConfi... |
| CVE-2025-70221 | CRITICAL | 9.8 | 0.5% | Mar 4, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin. |
| CVE-2025-46108 | CRITICAL | 9.8 | 0.6% | Mar 4, 2026 | D-link Dir-513 A1FW110 is vulnerable to Buffer Overflow in the function formTcpipSetup. |
| CVE-2025-70219 | CRITICAL | 9.8 | 0.5% | Mar 4, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the goform/formDeviceReboot. |
| CVE-2025-70226 | CRITICAL | 9.8 | 0.5% | Mar 4, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formEasySetupWizard. |
| CVE-2025-70223 | CRITICAL | 9.8 | 0.5% | Mar 4, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAdvNetwork. |
| CVE-2025-70220 | CRITICAL | 9.8 | 0.6% | Mar 4, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAutoDetecWAN_wizard4... |
| CVE-2025-70218 | CRITICAL | 9.8 | 0.6% | Mar 4, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via POST to the goform/formAdvFirewall component. |
| CVE-2025-69969 | CRITICAL | 9.6 | 0.5% | Mar 4, 2026 | A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Po... |
| CVE-2025-66944 | CRITICAL | 9.8 | 0.8% | Mar 4, 2026 | SQL Injection vulnerability in vran-dev databaseir v.1.0.7 and before allows a remote attacker to execute arbitrary code... |
| CVE-2025-66678 | CRITICAL | 9.8 | 0.6% | Mar 4, 2026 | An issue in the HwRwDrv.sys component of Nil Hardware Editor Hardware Read & Write Utility v1.25.11.26 and earlier allow... |
| CVE-2025-59786 | CRITICAL | 9.8 | 0.3% | Mar 4, 2026 | 2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to ... |
| CVE-2025-70240 | CRITICAL | 9.8 | 0.7% | Mar 3, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard51. |
| CVE-2025-70239 | CRITICAL | 9.8 | 0.6% | Mar 3, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard55. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now