2025 CVE Vulnerabilities

45,294 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-46633HIGH8.2Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an ...
CVE-2025-46632MEDIUM6.5Initialization vector (IV) reuse in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an attacker to ...
CVE-2025-46631MEDIUM6.5Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote ...
CVE-2025-46630MEDIUM6.5Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote ...
CVE-2025-46629MEDIUM6.5Lack of access controls in the 'ate' management binary of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote...
CVE-2025-46628HIGH7.3Lack of input validation/sanitization in the 'ate' management service in the Tenda RX2 Pro 16.03.30.14 allows an unautho...
CVE-2025-46627HIGH8.2Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telne...
CVE-2025-46626HIGH7.3Reuse of a static AES key and initialization vector for encrypted traffic to the 'ate' management service of the Tenda R...
CVE-2025-46625HIGH8.8Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a...
CVE-2025-46569HIGH7.4Open Policy Agent (OPA) is an open source, general-purpose policy engine. Prior to version 1.4.0, when run as a server, ...
CVE-2025-29763Rejected reason: “This CVE ID is Rejected and will not be used. The issue was determined to not be a vulnerability.”
CVE-2025-4174CRITICAL9.8A vulnerability, which was classified as critical, has been found in PHPGurukul COVID19 Testing Management System 1.0. A...
CVE-2025-3517MEDIUM6.3Incorrect privilege assignment in PAM JIT elevation feature in Devolutions Server 2025.1.5.0 and earlier allows a PAM us...
CVE-2025-36558MEDIUM6.1KUNBUS PiCtory version 2.11.1 and earlier are vulnerable to a cross-site-scripting attack via the sso_token used for aut...
CVE-2025-36521HIGH8.8MicroDicom DICOM Viewer is vulnerable to an out-of-bounds read which may allow an attacker to cause memory corruption wi...
CVE-2025-35996CRITICAL9KUNBUS PiCtory version 2.11.1 and earlier are vulnerable when an authenticated remote attacker crafts a special filename...
CVE-2025-35975HIGH8.8MicroDicom DICOM Viewer is vulnerable to an out-of-bounds write which may allow an attacker to execute arbitrary code. T...
CVE-2025-32011CRITICAL9.8KUNBUS PiCtory versions 2.5.0 through 2.11.1 have an authentication bypass vulnerability where a remote attacker can byp...
CVE-2025-24522CRITICAL10KUNBUS Revolution Pi OS Bookworm 01/2025 is vulnerable because authentication is not configured by default for the Node-...
CVE-2025-46568HIGH7.5Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. Prior to ve...
CVE-2025-46567HIGH7.8LLama Factory enables fine-tuning of large language models. Prior to version 1.0.0, a critical vulnerability exists in t...
CVE-2025-46566CRITICAL9.8DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.9, authenticated users can complete RCE...
CVE-2025-46565MEDIUM5.3Vite is a frontend tooling framework for javascript. Prior to versions 6.3.4, 6.2.7, 6.1.6, 5.4.19, and 4.5.14, the cont...
CVE-2025-46345MEDIUM6.9Auth0 Account Link Extension is an extension aimed to help link accounts easily. Versions 2.3.4 to 2.6.6 do not verify t...
CVE-2025-46337CRITICAL10ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now