2025 CVE Vulnerabilities

45,280 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-29813CRITICAL9.8Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges ov...
CVE-2025-27720CRITICAL9.3The Pixmeo Osirix MD Web Portal sends credential information without encryption, which could allow an attacker to steal ...
CVE-2025-27578HIGH8.7Pixmeo OsiriX MD is vulnerable to a use after free scenario, which could allow an attacker to upload a crafted DICOM fil...
CVE-2025-1331HIGH7.8IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on t...
CVE-2025-1330HIGH7.8IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1  could allow a local user to execute arbitrary code on ...
CVE-2025-1329HIGH7.8IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on t...
CVE-2025-28074MEDIUM6.1phpList before 3.6.15 is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization in lt.php. The vuln...
CVE-2025-4475Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-46833MEDIUM4.6Programs/P73_SimplePythonEncryption.py illustrates a simple Python encryption example using the RSA Algorithm. In versio...
CVE-2025-46812LOW2Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Versions prior to 2.1.15 are vulnerable to...
CVE-2025-46712LOW3.7Erlang/OTP is a set of libraries for the Erlang programming language. In versions prior to OTP-27.3.4 (for OTP-27), OTP-...
CVE-2025-46336MEDIUM4.2Rack::Session is a session management implementation for Rack. In versions starting from 2.0.0 to before 2.1.1, when usi...
CVE-2025-45798CRITICAL9.8A command execution vulnerability exists in the TOTOLINK A950RG V4.1.2cu.5204_B20210112. The vulnerability is located in...
CVE-2025-45797CRITICAL9.8TOTOlink A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability. The vulnerability arises from the impr...
CVE-2025-45790CRITICAL9.8TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the priority parameter in the setMacQos interface of /li...
CVE-2025-45789CRITICAL9.8TOTOLINK A3100R V5.9c.1527 is vulnerable to buffer overflow via the urlKeyword parameter in setParentalRules.
CVE-2025-45788CRITICAL9.8TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the comment parameter in setMacFilterRules.
CVE-2025-45787CRITICAL9.8TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow viathe comment parameter in setIpPortFilterRules.
CVE-2025-44023MEDIUM6.5An issue in dlink DNS-320 v.1.00 and DNS-320LW v.1.01.0914.20212 allows an attacker to execute arbitrary via the account...
CVE-2025-28073MEDIUM6.1phpList before 3.6.15 is vulnerable to Reflected Cross-Site Scripting (XSS) via the /lists/dl.php endpoint. An attacker ...
CVE-2025-27695MEDIUM4.9Dell Wyse Management Suite, versions prior to WMS 5.1 contain an Authentication Bypass by Spoofing vulnerability. A high...
CVE-2025-0505CRITICAL10On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain ...
CVE-2025-4098HIGH8.4Horner Automation Cscape version 10.0 (10.0.415.2) SP1 is vulnerable to an out-of-bounds read vulnerability that could a...
CVE-2025-30102MEDIUM5.5Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.1.0, contains an out-of-bounds write vulnerability. A local low pri...
CVE-2025-30101MEDIUM6.3Dell PowerScale OneFS, versions 9.8.0.0 through 9.10.1.0, contain a time-of-check time-of-use (TOCTOU) race condition vu...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now