2025 CVE Vulnerabilities

45,277 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-48866HIGH7.5ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions ...
CVE-2025-45542HIGH7.3SQL injection vulnerability in the registrationform endpoint of CloudClassroom-PHP-Project v1.0. The pass parameter is v...
CVE-2025-44115MEDIUM5.4A vulnerability has been found in Cotonti Siena v0.9.25. Affected by this vulnerability is the file /admin.php?m=config&...
CVE-2025-44172MEDIUM6.5Tenda AC6 V15.03.05.16 was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagement ...
CVE-2025-37096CRITICAL9.8A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
CVE-2025-37095CRITICAL9.8A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software.
CVE-2025-20001MEDIUM6.5An out-of-bounds read vulnerability exists in High-Logic FontCreator 15.0.0.3015. A specially crafted font file can trig...
CVE-2025-5447CRITICAL9.8A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002...
CVE-2025-37094CRITICAL9.1A directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software.
CVE-2025-37093CRITICAL9.8An authentication bypass vulnerability exists in HPE StoreOnce Software.
CVE-2025-37092CRITICAL9.8A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
CVE-2025-37091CRITICAL9.8A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
CVE-2025-37090CRITICAL9.8A server-side request forgery vulnerability exists in HPE StoreOnce Software.
CVE-2025-37089CRITICAL9.8A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
CVE-2025-5446CRITICAL9.8A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002...
CVE-2025-5445CRITICAL9.8A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002...
CVE-2025-48745Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-49113. Reason: This candidate is a reservation d...
CVE-2025-46806MEDIUM6.9A Use of Out-of-range Pointer Offset vulnerability in sslh leads to denial of service on some architectures.This issue a...
CVE-2025-26396HIGH7.8The SolarWinds Dameware Mini Remote Control was determined to be affected by Incorrect Permissions Local Privilege Escal...
CVE-2025-5444CRITICAL9.8A vulnerability has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.0...
CVE-2025-5443CRITICAL9.8A vulnerability, which was classified as critical, was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE900...
CVE-2025-48990HIGH8.6NeKernal is a free and open-source operating system stack. Version 0.0.2 has a 1-byte heap overflow in `rt_copy_memory`,...
CVE-2025-48958MEDIUM5.4Froxlor is open source server administration software. Prior to version 2.2.6, an HTML Injection vulnerability in the cu...
CVE-2025-48957HIGH7.5AstrBot is a large language model chatbot and development framework. A path traversal vulnerability present in versions ...
CVE-2025-48955MEDIUM6.2Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in vers...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now