2025 CVE Vulnerabilities

45,280 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-47423MEDIUM5.8Personal Weather Station Dashboard 12_lts allows unauthenticated remote attackers to read arbitrary files via ../ direct...
CVE-2025-47203MEDIUM4.5dbclient in Dropbear SSH before 2025.88 allows command injection via an untrusted hostname argument, because a shell is ...
CVE-2025-46828CRITICAL9.8WeGIA is a web manager for charitable institutions. An unauthenticated SQL Injection vulnerability was identified in ve...
CVE-2025-46824LOW3.1The Discourse Code Review Plugin allows users to review GitHub commits on Discourse. Prior to commit eed3a80, an attacke...
CVE-2025-32821HIGH7.2A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges ...
CVE-2025-32820HIGH8.8A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal...
CVE-2025-32819HIGH8.8A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversa...
CVE-2025-20223MEDIUM4.7A vulnerability in Cisco Catalyst Center, formerly Cisco DNA Center, could allow an authenticated, remote attacker to re...
CVE-2025-20221CRITICAL9.1A vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote ...
CVE-2025-20216MEDIUM4.3A vulnerability in the web interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an una...
CVE-2025-20214MEDIUM4.3A vulnerability in the Network Configuration Access Control Module (NACM) of Cisco IOS XE Software could allow an authen...
CVE-2025-20213MEDIUM5.5A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated...
CVE-2025-20210HIGH7.3A vulnerability in the management API of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticate...
CVE-2025-20202HIGH7.4A vulnerability in Cisco IOS XE Wireless Controller Software could allow an unauthenticated, adjacent attacker to cause ...
CVE-2025-20201MEDIUM6.7A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15...
CVE-2025-20200HIGH8.2A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15...
CVE-2025-20199HIGH8.2A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15...
CVE-2025-20198HIGH8.2A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15...
CVE-2025-20197HIGH8.2A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15...
CVE-2025-20196MEDIUM5.3A vulnerability in the Cisco IOx application hosting environment of Cisco IOS Software and Cisco IOS XE Software could a...
CVE-2025-20195MEDIUM4.3A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote at...
CVE-2025-20194MEDIUM5.4A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, low-privile...
CVE-2025-20193MEDIUM6.5A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, low-privile...
CVE-2025-20192HIGH7.7A vulnerability in the Internet Key Exchange version 1 (IKEv1) implementation of Cisco IOS XE Software could allow an au...
CVE-2025-20191HIGH7.4A vulnerability in the Switch Integrated Security Features (SISF) of Cisco IOS Software, Cisco IOS XE Software, Cisco NX...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now