2025 CVE Vulnerabilities

45,266 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-5832MEDIUM6.8Pioneer DMH-WT7600NEX Software Update Signing Insufficient Verification of Data Authenticity Vulnerability. This vulnera...
CVE-2025-5830HIGH8.8Autel MaxiCharger AC Wallbox Commercial DLB_SlaveRegister Heap-based Buffer Overflow Remote Code Execution Vulnerability...
CVE-2025-5829MEDIUM6.8Autel MaxiCharger AC Wallbox Commercial autocharge Stack-based Buffer Overflow Remote Code Execution Vulnerability. This...
CVE-2025-5828MEDIUM6.8Autel MaxiCharger AC Wallbox Commercial wLength Buffer Overflow Remote Code Execution Vulnerability. This vulnerability ...
CVE-2025-5827HIGH8.8Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Stack-based Buffer Overflow Remote Code Execution Vulnerab...
CVE-2025-5826MEDIUM6.3Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Misinterpretation of Input Vulnerability. This vulnerabili...
CVE-2025-5825HIGH7.5Autel MaxiCharger AC Wallbox Commercial Firmware Downgrade Remote Code Execution Vulnerability. This vulnerability allow...
CVE-2025-5824HIGH7.5Autel MaxiCharger AC Wallbox Commercial Origin Validation Error Authentication Bypass Vulnerability. This vulnerability ...
CVE-2025-5823MEDIUM6.5Autel MaxiCharger AC Wallbox Commercial Serial Number Exposed Dangerous Method Information Disclosure Vulnerability. Thi...
CVE-2025-5822HIGH8.8Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This ...
CVE-2025-49550MEDIUM4.3Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Author...
CVE-2025-49549LOW2.7Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Author...
CVE-2025-45332HIGH7.5vkoskiv c-ray 1.1 contains a Null Pointer Dereference (NPD) vulnerability in the parse_mtllib function of its data proce...
CVE-2025-6617HIGH8.8A vulnerability was found in D-Link DIR-619L 2.06B01 and classified as critical. This issue affects the function formAdv...
CVE-2025-6616HIGH8.8A vulnerability has been found in D-Link DIR-619L 2.06B01 and classified as critical. This vulnerability affects the fun...
CVE-2025-6442MEDIUM5.9Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arb...
CVE-2025-5015HIGH8.8A cross-site scripting vulnerability exists in the AccuWeather and Custom RSS widget that allows an unauthenticated user...
CVE-2025-52999HIGH8.7jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Pr...
CVE-2025-52894HIGH7.5OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certifi...
CVE-2025-52893MEDIUM4.5OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certifi...
CVE-2025-52890HIGH8.1Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus vers...
CVE-2025-52889LOW3.4Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus vers...
CVE-2025-52576MEDIUM5.3Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.46, Kanboard is vul...
CVE-2025-52569MEDIUM6.6GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 5.9.1 lack input validation of i...
CVE-2025-52483CRITICAL9.8Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General regi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now