2025 CVE Vulnerabilities

45,295 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-27580HIGH7.5NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 generates predictable tokens (that de...
CVE-2025-25046LOW3.7IBM InfoSphere Information Server 11.7 DataStage Flow Designer  transmits sensitive information via URL or query parame...
CVE-2025-25045MEDIUM4.3IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical erro...
CVE-2025-46400MEDIUM5.5In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input ...
CVE-2025-46399MEDIUM5.5A flaw was found in fig2dev. This vulnerability allows availability via local input manipulation via genge_itp_spline fu...
CVE-2025-46398MEDIUM5.5In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation v...
CVE-2025-46397HIGH7.8A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spli...
CVE-2025-32818HIGH7.5A Null Pointer Dereference vulnerability in the SonicOS SSLVPN Virtual office interface allows a remote, unauthenticated...
CVE-2025-28169HIGH8.1BYD QIN PLUS DM-i Dilink OS v3.0_13.1.7.2204050.1 to v3.0_13.1.7.2312290.1_0 was discovered to cend broadcasts to the ma...
CVE-2025-3673Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-3092.. Reason: This candidate is a...
CVE-2025-3907MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Drupal Search API Solr allows Cross Site Request Forgery.This issue a...
CVE-2025-3904HIGH7.3Vulnerability in Drupal Sportsleague.This issue affects Sportsleague: *.*.
CVE-2025-3903HIGH7.3Vulnerability in Drupal UEditor - 百度编辑器.This issue affects UEditor - 百度编辑器: *.*.
CVE-2025-3902MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Block Class...
CVE-2025-3901MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Bootstrap S...
CVE-2025-3900MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Colorbox al...
CVE-2025-2773HIGH7.2BEC Technologies Multiple Routers sys ping Command Injection Remote Code Execution Vulnerability. This vulnerability all...
CVE-2025-2772MEDIUM6.5BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure Vulnerability. This vulner...
CVE-2025-2771MEDIUM5.3BEC Technologies Multiple Routers Authentication Bypass Vulnerability. This vulnerability allows remote attackers to byp...
CVE-2025-2770MEDIUM6.5BEC Technologies Multiple Routers Cleartext Password Storage Information Disclosure Vulnerability. This vulnerability al...
CVE-2025-2769HIGH7.8Bdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows loc...
CVE-2025-2768HIGH7.8Bdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows loc...
CVE-2025-2767CRITICAL9.6Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote...
CVE-2025-2765HIGH8.8CarlinKit CPC200-CCPA Wireless Hotspot Hard-Coded Credentials Authentication Bypass Vulnerability. This vulnerability al...
CVE-2025-2764HIGH8CarlinKit CPC200-CCPA update.cgi Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vul...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now