2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-66506HIGH7.5Fulcio is a free-to-use certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identit...
CVE-2025-66238HIGH7.4DCIM dcTrack allows an attacker to misuse certain remote access features. An authenticated user with access to the appli...
CVE-2025-53704HIGH8.7The password reset mechanism for the Pivot client application is weak, and it may allow an attacker to take over the acc...
CVE-2025-1547HIGH7.2A stack-based buffer overflow vulnerability [CWE-121] in WatchGuard Fireware OS's certificate request command could allo...
CVE-2025-1545HIGH7.5An XPath Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensi...
CVE-2025-13932HIGH8.3The SolisCloud API suffers from a Broken Access Control vulnerability, specifically an Insecure Direct Object Reference ...
CVE-2025-12196HIGH7.2An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to exe...
CVE-2025-12195HIGH7.2An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to exe...
CVE-2025-12026HIGH7.2An Out-of-bounds Write vulnerability in WatchGuard Fireware OS’s certificate request command could allow an authenticate...
CVE-2025-11838HIGH7.5A memory corruption vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker to trigger a Denial of...
CVE-2025-10285HIGH7.4The web interface of the Silicon Labs Simplicity Device Manager is exposed publicly and can be used to extract the NTLMv...
CVE-2025-66575HIGH7.8VeeVPN 1.6.1 contains an unquoted service path vulnerability in the VeePNService that allows remote attackers to execute...
CVE-2025-66573HIGH7.5Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive info...
CVE-2025-66555HIGH8.8AirKeyboard iOS App 1.0.5 contains a missing authentication vulnerability that allows unauthenticated attackers to type ...
CVE-2025-63896HIGH7.6An issue in the Bluetooth Human Interface Device (HID) of JXL 9 Inch Car Android Double Din Player Android v12.0 allows ...
CVE-2025-55948HIGH7.3This vulnerability fundamentally arises from yzcheng90 X-SpringBoot 6.0's implementation of role-based access control (R...
CVE-2025-27935HIGH8.6The OTP Integration Kit for PingFederate fails to enforce HTTP method validation and state validation properly. The serv...
CVE-2025-13543HIGH8.8The PostGallery plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in th...
CVE-2025-65958HIGH7.1Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a Se...
CVE-2025-65883HIGH8.4A vulnerability has been identified in Genexis Platinum P4410 router (Firmware P4410-V2–1.41) that allows a local networ...
CVE-2025-12097HIGH8.7There is a relative path traversal vulnerability in the NI System Web Server that may result in information disclosure. ...
CVE-2025-65945HIGH7.5auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth...
CVE-2025-65637HIGH7.5A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line pa...
CVE-2025-14016HIGH8.1A security vulnerability has been detected in macrozheng mall-swarm up to 1.0.3. Affected is the function delete of the ...
CVE-2025-63363HIGH7.5A lack of Management Frame Protection in Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now