2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-70560HIGH8.4Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application us...
CVE-2025-70559MEDIUM6.5pdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The libra...
CVE-2025-70311MEDIUM6.5JEEWMS 1.0 is vulnerable to SQL Injection. Attackers can inject malicious SQL statements through the id1 and id2 paramet...
CVE-2025-69983CRITICAL9.8FUXA v1.2.7 allows Remote Code Execution (RCE) via the project import functionality. The application does not properly s...
CVE-2025-69981CRITICAL9.8FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks aut...
CVE-2025-69971CRITICAL9.8FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-code...
CVE-2025-69970CRITICAL9.3FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' ...
CVE-2025-69875HIGH7.8A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient val...
CVE-2025-69848MEDIUM5.4NetBox is an open-source infrastructure resource modeling and IP address management platform. A reflected cross-site scr...
CVE-2025-69431MEDIUM6.1The ZSPACE Q2C NAS contains a vulnerability related to incorrect symbolic link following. Attackers can format a USB dri...
CVE-2025-69430MEDIUM6.1An Incorrect Symlink Follow vulnerability exists in multiple Yottamaster NAS devices, including DM2 (version equal to or...
CVE-2025-69429MEDIUM6.1The ORICO NAS CD3510 (version V1.9.12 and below) contains an Incorrect Symlink Follow vulnerability that could be exploi...
CVE-2025-67189MEDIUM6.5A buffer overflow vulnerability exists in the setParentalRules interface of TOTOLINK A950RG V4.1.2cu.5204_B20210112. The...
CVE-2025-67188CRITICAL9.8A buffer overflow vulnerability exists in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The issue resides in the setRadvdCfg ...
CVE-2025-67187CRITICAL9.8A stack-based buffer overflow vulnerability was identified in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The flaw exists i...
CVE-2025-67186CRITICAL9.8TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability in the setUrlFilterRules interface of /...
CVE-2025-66374HIGH7.8CyberArk Endpoint Privilege Manager Agent through 25.10.0 allows a local user to achieve privilege escalation through po...
CVE-2025-65924MEDIUM4.1ERPNext thru 15.88.1 does not sanitize or remove certain HTML tags specifically `<a>` hyperlinks in fields that are inte...
CVE-2025-65923MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was discovered within the CSV import mechanism of ERPNext thru 15.88.1...
CVE-2025-65875CRITICAL9.8An arbitrary file upload vulnerability in the AddFont() function of FPDF v1.86 and earlier allows attackers to execute a...
CVE-2025-63624CRITICAL9.8SQL Injection vulnerability in Shandong Kede Electronics Co., Ltd IoT smart water meter monitoring platform v.1.0 allows...
CVE-2025-63372MEDIUM4.3Articentgroup Zip Rar Extractor Tool 1.345.93.0 is vulnerable to Directory Traversal. The vulnerability resides in the Z...
CVE-2025-62599HIGH7.5eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management ...
CVE-2025-61506CRITICAL9.8An issue was discovered in MediaCrush thru 1.0.1 allowing remote unauthenticated attackers to upload arbitrary files of ...
CVE-2025-60865HIGH7.8Insecure Permissions vulnerability in avanquest Driver Updater v.9.1.57803.1174 allows a local attacker to escalate priv...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now