2025 CVE Vulnerabilities

45,279 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-44897CRITICAL9.8FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bytftp_srvip parameter in the web_tool_up...
CVE-2025-44896CRITICAL9.8FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bindEditMACName parameter in the web_acl_...
CVE-2025-44894CRITICAL9.8FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radDftParamKey parameter in the web_radiu...
CVE-2025-44891CRITICAL9.8FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_v3host_...
CVE-2025-44883CRITICAL9.8FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the tacIp parameter in the web_tacplus_server...
CVE-2025-44882CRITICAL9.8A command injection vulnerability in the component /cgi-bin/firewall.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to ...
CVE-2025-44880CRITICAL9.8A command injection vulnerability in the component /cgi-bin/adm.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execu...
CVE-2025-4997HIGH7.1A vulnerability, which was classified as problematic, was found in H3C R2+ProG up to 200R004. Affected is the function U...
CVE-2025-48056MEDIUM5.3Hubble is a fully distributed networking and security observability platform for cloud native workloads. Prior to versio...
CVE-2025-44893CRITICAL9.8FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ruleNamekey parameter in the web_acl_mgmt...
CVE-2025-44890CRITICAL9.8FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_notifyv...
CVE-2025-44888CRITICAL9.8FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the stp_conf_name parameter in the web_stp_gl...
CVE-2025-44887CRITICAL9.8FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radIpkey parameter in the web_radiusSrv_p...
CVE-2025-44886CRITICAL9.8FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the byruleEditName parameter in the web_acl_m...
CVE-2025-44885CRITICAL9.8FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the remote_ip parameter in the web_snmpv3_rem...
CVE-2025-44884CRITICAL9.8FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the web_sys_infoContact_post function.
CVE-2025-44881CRITICAL9.8A command injection vulnerability in the component /cgi-bin/qos.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execu...
CVE-2025-4996MEDIUM4.8A vulnerability, which was classified as problematic, has been found in Intelbras RF 301K 1.1.5. This issue affects some...
CVE-2025-47290MEDIUM5.9containerd is a container runtime. A time-of-check to time-of-use (TOCTOU) vulnerability was found in containerd v2.1.0....
CVE-2025-4364HIGH8.7The affected products could allow an unauthenticated attacker to access system information that could enable further acc...
CVE-2025-48391HIGH7.5In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API
CVE-2025-47854MEDIUM6.1In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page
CVE-2025-47853MEDIUM5.4In JetBrains TeamCity before 2025.03.2 stored XSS via Jira integration was possible
CVE-2025-47852MEDIUM5.4In JetBrains TeamCity before 2025.03.2 stored XSS via YouTrack integration was possible
CVE-2025-47851MEDIUM5.4In JetBrains TeamCity before 2025.03.2 stored XSS via GitHub Checks Webhook was possible

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now