2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-11838HIGH7.5A memory corruption vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker to trigger a Denial of...
CVE-2025-10285HIGH7.4The web interface of the Silicon Labs Simplicity Device Manager is exposed publicly and can be used to extract the NTLMv...
CVE-2025-66575HIGH7.8VeeVPN 1.6.1 contains an unquoted service path vulnerability in the VeePNService that allows remote attackers to execute...
CVE-2025-66573HIGH7.5Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive info...
CVE-2025-66555HIGH8.8AirKeyboard iOS App 1.0.5 contains a missing authentication vulnerability that allows unauthenticated attackers to type ...
CVE-2025-66237HIGH8.4DCIM dcTrack platforms utilize default and hard-coded credentials for access. An attacker could use these credentials to...
CVE-2025-63896HIGH7.6An issue in the Bluetooth Human Interface Device (HID) of JXL 9 Inch Car Android Double Din Player Android v12.0 allows ...
CVE-2025-55948HIGH7.3This vulnerability fundamentally arises from yzcheng90 X-SpringBoot 6.0's implementation of role-based access control (R...
CVE-2025-27935HIGH8.6The OTP Integration Kit for PingFederate fails to enforce HTTP method validation and state validation properly. The serv...
CVE-2025-13543HIGH8.8The PostGallery plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in th...
CVE-2025-65958HIGH7.1Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a Se...
CVE-2025-65883HIGH8.4A vulnerability has been identified in Genexis Platinum P4410 router (Firmware P4410-V2–1.41) that allows a local networ...
CVE-2025-12097HIGH8.7There is a relative path traversal vulnerability in the NI System Web Server that may result in information disclosure. ...
CVE-2025-65945HIGH7.5auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth...
CVE-2025-65637HIGH7.5A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line pa...
CVE-2025-14016HIGH8.1A security vulnerability has been detected in macrozheng mall-swarm up to 1.0.3. Affected is the function delete of the ...
CVE-2025-63363HIGH7.5A lack of Management Frame Protection in Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V...
CVE-2025-14012HIGH7.2A vulnerability was determined in JIZHICMS up to 2.5.5. The affected element is the function deleteAll/findAll/delete of...
CVE-2025-14011HIGH7.2A vulnerability was found in JIZHICMS up to 2.5.5. Impacted is the function commentlist of the file /index.php/admins/Co...
CVE-2025-66287HIGH8.8A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper me...
CVE-2025-63364HIGH7.5Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.00...
CVE-2025-57213HIGH7.5Incorrect access control in the component orderService.queryObject of platform v1.0.0 allows attackers to access sensiti...
CVE-2025-57212HIGH7.5Incorrect access control in the component ApiOrderService.java of platform v1.0.0 allows attackers to access sensitive i...
CVE-2025-57210HIGH7.5Incorrect access control in the component ApiPayController.java of platform v1.0.0 allows attackers to access sensitive ...
CVE-2025-56427HIGH7.5Directory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitive information via th...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now