2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-70234CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetQoS.
CVE-2025-70241CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWANType_Wizard5.
CVE-2025-70237CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetPortTr.
CVE-2025-70236CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDomainFilter.
CVE-2025-66945CRITICAL9.1A path traversal vulnerability exists in the ZIP extraction API of Zdir Pro 4.x. When a crafted ZIP archive is processed...
CVE-2025-14923CRITICAL9.8IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could prov...
CVE-2025-70821CRITICAL9.8renren-secuity before v5.5.0 is vulnerable to SQL Injection in the BaseServiceImpl.java component
CVE-2025-57622CRITICAL9.8An issue in Step-Video-T2V allows a remote attacker to execute arbitrary code via the /vae-api , /caption-api , feature ...
CVE-2025-59059CRITICAL9.8Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users ...
CVE-2025-48609CRITICAL9.1In multiple functions of MmsProvider.java, there is a possible way to arbitrarily delete files which affect telephony, S...
CVE-2025-52998CRITICAL9.8Chamilo is a learning management system. Prior to version 1.11.30, in the application, deserialization of data is perfor...
CVE-2025-50199CRITICAL9.1Chamilo is a learning management system. Prior to version 1.11.30, there is a blind SSRF vulnerability in /index.php via...
CVE-2025-50192CRITICAL9.8Chamilo is a learning management system. Prior to version 1.11.30, there is a time-based SQL Injection in found in /main...
CVE-2025-50190CRITICAL9.8Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via the GET ope...
CVE-2025-50187CRITICAL9.8Chamilo is a learning management system. Prior to version 1.11.28, parameter from SOAP request is evaluated without filt...
CVE-2025-14532CRITICAL9.8DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension...
CVE-2025-12462CRITICAL9.3A Blind SQL injection vulnerability has been identified in DobryCMS.  A remote unauthenticated attacker is able to injec...
CVE-2025-30044CRITICAL9.4In the endpoints "/cgi-bin/CliniNET.prd/utils/usrlogstat_simple.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", "/cgi-...
CVE-2025-30035CRITICAL9The vulnerability enables an attacker to fully bypass authentication in CGM CLININET and gain access to any active user ...
CVE-2025-15498CRITICAL9.3Pro3W CMS if vulnerable to SQL injection attacks. Improper neutralization of input provided into a login form allows an ...
CVE-2025-11252CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology ...
CVE-2025-11251CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dayneks Software I...
CVE-2025-12981CRITICAL9.8The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This i...
CVE-2025-50857CRITICAL9.8ZenTaoPMS v18.11 through v21.6.beta is vulnerable to Directory Traversal in /module/ai/control.php. This allows attacker...
CVE-2025-69771CRITICAL9.6Cross-Site Scripting (XSS) vulnerability in the subtitle loading function of the asbplayer Chrome Extension version 1.14...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now