2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-70223 | CRITICAL | 9.8 | 0.5% | Mar 4, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAdvNetwork. |
| CVE-2025-70220 | CRITICAL | 9.8 | 0.6% | Mar 4, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAutoDetecWAN_wizard4... |
| CVE-2025-70218 | CRITICAL | 9.8 | 0.6% | Mar 4, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via POST to the goform/formAdvFirewall component. |
| CVE-2025-69969 | CRITICAL | 9.6 | 0.5% | Mar 4, 2026 | A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Po... |
| CVE-2025-66944 | CRITICAL | 9.8 | 0.8% | Mar 4, 2026 | SQL Injection vulnerability in vran-dev databaseir v.1.0.7 and before allows a remote attacker to execute arbitrary code... |
| CVE-2025-66678 | CRITICAL | 9.8 | 0.6% | Mar 4, 2026 | An issue in the HwRwDrv.sys component of Nil Hardware Editor Hardware Read & Write Utility v1.25.11.26 and earlier allow... |
| CVE-2025-59786 | CRITICAL | 9.8 | 0.3% | Mar 4, 2026 | 2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to ... |
| CVE-2025-70240 | CRITICAL | 9.8 | 0.7% | Mar 3, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard51. |
| CVE-2025-70239 | CRITICAL | 9.8 | 0.6% | Mar 3, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard55. |
| CVE-2025-70234 | CRITICAL | 9.8 | 0.7% | Mar 3, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetQoS. |
| CVE-2025-70241 | CRITICAL | 9.8 | 0.6% | Mar 3, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWANType_Wizard5. |
| CVE-2025-70237 | CRITICAL | 9.8 | 0.7% | Mar 3, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetPortTr. |
| CVE-2025-70236 | CRITICAL | 9.8 | 0.6% | Mar 3, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDomainFilter. |
| CVE-2025-66945 | CRITICAL | 9.1 | 0.5% | Mar 3, 2026 | A path traversal vulnerability exists in the ZIP extraction API of Zdir Pro 4.x. When a crafted ZIP archive is processed... |
| CVE-2025-14923 | CRITICAL | 9.8 | 0.2% | Mar 3, 2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could prov... |
| CVE-2025-70821 | CRITICAL | 9.8 | 0.4% | Mar 3, 2026 | renren-secuity before v5.5.0 is vulnerable to SQL Injection in the BaseServiceImpl.java component |
| CVE-2025-57622 | CRITICAL | 9.8 | 0.5% | Mar 3, 2026 | An issue in Step-Video-T2V allows a remote attacker to execute arbitrary code via the /vae-api , /caption-api , feature ... |
| CVE-2025-59059 | CRITICAL | 9.8 | 1.2% | Mar 3, 2026 | Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users ... |
| CVE-2025-48609 | CRITICAL | 9.1 | 0.3% | Mar 2, 2026 | In multiple functions of MmsProvider.java, there is a possible way to arbitrarily delete files which affect telephony, S... |
| CVE-2025-52998 | CRITICAL | 9.8 | 0.4% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, in the application, deserialization of data is perfor... |
| CVE-2025-50199 | CRITICAL | 9.1 | 0.4% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is a blind SSRF vulnerability in /index.php via... |
| CVE-2025-50192 | CRITICAL | 9.8 | 0.6% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is a time-based SQL Injection in found in /main... |
| CVE-2025-50190 | CRITICAL | 9.8 | 0.6% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via the GET ope... |
| CVE-2025-50187 | CRITICAL | 9.8 | 0.9% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.28, parameter from SOAP request is evaluated without filt... |
| CVE-2025-14532 | CRITICAL | 9.8 | 0.5% | Mar 2, 2026 | DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now