2025 CVE Vulnerabilities

45,277 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-48495MEDIUM5.4Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. By renaming the friendly n...
CVE-2025-46807HIGH8.7A Allocation of Resources Without Limits or Throttling vulnerability in sslh allows attackers to easily exhaust the file...
CVE-2025-5442CRITICAL9.8A vulnerability, which was classified as critical, has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and ...
CVE-2025-5441CRITICAL9.8A vulnerability classified as critical was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.00...
CVE-2025-48494MEDIUM5.4Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. When using end-to-end encr...
CVE-2025-47289CRITICAL9CE Phoenix is a free, open-source eCommerce platform. A stored cross-site scripting (XSS) vulnerability was discovered i...
CVE-2025-47272MEDIUM5.5The CE Phoenix eCommerce platform, starting in version 1.0.9.7 and prior to version 1.1.0.3, allowed logged-in users to ...
CVE-2025-3454MEDIUM5This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash...
CVE-2025-29785HIGH7.5quic-go is an implementation of the QUIC protocol in Go. The loss recovery logic for path probe packets that was added i...
CVE-2025-1246HIGH7.8Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Bifrost GPU Userspace D...
CVE-2025-0819HIGH7.8Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge...
CVE-2025-0073HIGH7.8Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver al...
CVE-2025-5440HIGH8.8A vulnerability classified as critical has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.0...
CVE-2025-5439HIGH8.8A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002...
CVE-2025-3260HIGH8.3A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard a...
CVE-2025-1750CRITICAL9.8An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12...
CVE-2025-5455HIGH8.4An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkRe...
CVE-2025-5438HIGH8.8A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002...
CVE-2025-5437MEDIUM6.9A vulnerability classified as critical has been found in Multilaser Sirius RE016 MLT1.0. Affected is an unknown function...
CVE-2025-5436MEDIUM6.9A vulnerability was found in Multilaser Sirius RE016 MLT1.0. It has been rated as problematic. This issue affects some u...
CVE-2025-5435HIGH7.3A vulnerability was found in Marwal Infotech CMS 1.0. It has been declared as critical. This vulnerability affects unkno...
CVE-2025-5113HIGH8.6The Diviotec professional series exposes a web interface. One endpoint is vulnerable to arbitrary command injection and ...
CVE-2025-0358HIGH8.8During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Devi...
CVE-2025-0325MEDIUM4.3A Guard Tour VAPIX API parameter allowed the use of arbitrary values and can be incorrectly called, allowing an attacker...
CVE-2025-0324HIGH8.8The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain admini...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now