2025 CVE Vulnerabilities

45,279 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-26685MEDIUM6.5Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an a...
CVE-2025-26684MEDIUM6.7External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privil...
CVE-2025-26677HIGH7.5Uncontrolled resource consumption in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over...
CVE-2025-24063HIGH7.8Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2025-21264HIGH7.1Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a se...
CVE-2025-0035HIGH7.3Unquoted search path within AMD Cloud Manageability Service can allow a local attacker to escalate privileges, potential...
CVE-2025-4428HIGH8.8Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms all...
CVE-2025-4427HIGH7.5An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to a...
CVE-2025-47278LOW1.8Flask is a web server gateway interface (WSGI) web application framework. In Flask 3.1.0, the way fallback key configura...
CVE-2025-47276HIGH7.5Actualizer is a single shell script solution to allow developers and embedded engineers to create Debian operating syste...
CVE-2025-47204MEDIUM6.1An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the sour...
CVE-2025-46721MEDIUM6.1nosurf is cross-site request forgery (CSRF) protection middleware for Go. A vulnerability in versions prior to 1.2.0 all...
CVE-2025-45858CRITICAL9.8TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability via the FUN_00459fdc f...
CVE-2025-45857CRITICAL9.8EDIMAX CV7428NS v1.20 was discovered to contain a remote code execution (RCE) vulnerability via the command parameter in...
CVE-2025-31493CRITICAL9.1Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 aff...
CVE-2025-30207HIGH7.5Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 aff...
CVE-2025-28056CRITICAL9.8rebuild v3.9.0 through v3.9.3 has a SQL injection vulnerability in /admin/admin-cli/exec component.
CVE-2025-28055HIGH7.5upset-gal-web v7.1.0 /api/music/v1/cover.ts contains an arbitrary file read vulnerabilit
CVE-2025-22462CRITICAL9.8An authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Se...
CVE-2025-45867MEDIUM5.4TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the static_dns1 parameter in the f...
CVE-2025-45866MEDIUM5.4TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolEnd parameter in the f...
CVE-2025-45864MEDIUM5.4TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolStart parameter in the...
CVE-2025-45859MEDIUM5.4TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the bandstr parameter in the formM...
CVE-2025-44831CRITICAL9.8EngineerCMS v1.02 through v2.0.5 has a SQL injection vulnerability in the /project/addproject interface.
CVE-2025-44039MEDIUM5.1CP-XR-DE21-S -4G Router Firmware version 1.031.022 was discovered to contain insecure protections for its UART console. ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now