2025 CVE Vulnerabilities
45,294 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-44867 | MEDIUM | 6.3 | 1.1% | May 1, 2025 | Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetNetCheckTools function via th... |
| CVE-2025-44866 | MEDIUM | 6.3 | 1.1% | May 1, 2025 | Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the lev... |
| CVE-2025-44865 | MEDIUM | 6.3 | 1.1% | May 1, 2025 | Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the ena... |
| CVE-2025-44864 | MEDIUM | 6.3 | 1.1% | May 1, 2025 | Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the mod... |
| CVE-2025-44863 | MEDIUM | 6.5 | 0.9% | May 1, 2025 | TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process functio... |
| CVE-2025-44862 | MEDIUM | 6.3 | 0.9% | May 1, 2025 | TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the recvUpgradeNewFw fu... |
| CVE-2025-44861 | MEDIUM | 6.3 | 0.9% | May 1, 2025 | TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the CloudSrvUserdataVer... |
| CVE-2025-44860 | MEDIUM | 6.5 | 0.9% | May 1, 2025 | TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process functio... |
| CVE-2025-32890 | MEDIUM | 6.5 | 0.1% | May 1, 2025 | An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. It uses a custom implementation of e... |
| CVE-2025-32889 | HIGH | 8.8 | 0.2% | May 1, 2025 | An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The verification token used for sendin... |
| CVE-2025-32888 | HIGH | 8.8 | 0.2% | May 1, 2025 | An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. The verification token used for send... |
| CVE-2025-32887 | MEDIUM | 6.5 | 0.1% | May 1, 2025 | An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. A command channel includes the next ho... |
| CVE-2025-32886 | MEDIUM | 5.5 | 0.1% | May 1, 2025 | An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. All packets sent over RF are also sent... |
| CVE-2025-32885 | MEDIUM | 6.5 | 0.2% | May 1, 2025 | An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The app there makes it possible to inj... |
| CVE-2025-32884 | MEDIUM | 6.5 | 0.1% | May 1, 2025 | An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. By default, a GID is the user's phon... |
| CVE-2025-32883 | — | — | — | May 1, 2025 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-41722. Reason: This candidate is a reservation d... |
| CVE-2025-32882 | MEDIUM | 6.5 | 0.1% | May 1, 2025 | An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The app uses a custom implementation o... |
| CVE-2025-32881 | MEDIUM | 6.5 | 0.1% | May 1, 2025 | An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. By default, the GID is the user's phon... |
| CVE-2025-4173 | HIGH | 8.8 | 0.4% | May 1, 2025 | A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. Affected by this vulnerabili... |
| CVE-2025-44848 | MEDIUM | 6.5 | 0.9% | May 1, 2025 | TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the msg_process functi... |
| CVE-2025-44847 | MEDIUM | 6.3 | 0.9% | May 1, 2025 | TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the setWebWlanIdx func... |
| CVE-2025-44846 | MEDIUM | 6.3 | 0.9% | May 1, 2025 | TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the recvUpgradeNewFw f... |
| CVE-2025-44845 | MEDIUM | 6.5 | 0.9% | May 1, 2025 | TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the NTPSyncWithHost fu... |
| CVE-2025-44844 | MEDIUM | 6.5 | 0.9% | May 1, 2025 | TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the setUpgradeFW funct... |
| CVE-2025-44843 | MEDIUM | 6.5 | 1.0% | May 1, 2025 | TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVe... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now