2025 CVE Vulnerabilities

45,295 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-2763MEDIUM6.8CarlinKit CPC200-CCPA Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vulnerability ...
CVE-2025-2762HIGH7.8CarlinKit CPC200-CCPA Missing Root of Trust Local Privilege Escalation Vulnerability. This vulnerability allows local at...
CVE-2025-2761HIGH7.8GIMP FLI File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attacker...
CVE-2025-2760HIGH7.8GIMP XWD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers t...
CVE-2025-29526MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability in the search function of Q4 Inc Investor Relations Platform v5.147.1.2 allow...
CVE-2025-28028HIGH7.3TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2c...
CVE-2025-28025HIGH7.3TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2c...
CVE-2025-28022HIGH7.3TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in downloadFile.cgi through ...
CVE-2025-28021HIGH7.3TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the downloadFile.cgi thro...
CVE-2025-28020HIGH7.3TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through ...
CVE-2025-28019HIGH7.3TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi comp...
CVE-2025-28018HIGH7.3TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through ...
CVE-2025-28017MEDIUM6.5TOTOLINK A800R V4.1.2cu.5032_B20200408 is vulnerable to Command Injection in downloadFile.cgi via the QUERY_STRING param...
CVE-2025-1522MEDIUM6.5PostHog database_schema Server-Side Request Forgery Information Disclosure Vulnerability. This vulnerability allows remo...
CVE-2025-1521MEDIUM6.5PostHog slack_incoming_webhook Server-Side Request Forgery Information Disclosure Vulnerability. This vulnerability allo...
CVE-2025-1520HIGH8PostHog ClickHouse Table Functions SQL Injection Remote Code Execution Vulnerability. This vulnerability allows network-...
CVE-2025-1050HIGH8.8Sonos Era 300 Out-of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attack...
CVE-2025-1049HIGH8.8Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent...
CVE-2025-1048HIGH8.8Sonos Era 300 Speaker libsmb2 Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adja...
CVE-2025-1047HIGH7.8Luxion KeyShot PVS File Parsing Access of Uninitialized Pointer Remote Code Execution Vulnerability. This vulnerability ...
CVE-2025-1046HIGH7.8Luxion KeyShot SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote att...
CVE-2025-1045HIGH7.8Luxion KeyShot Viewer KSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabilit...
CVE-2025-46394LOW3.3In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal esc...
CVE-2025-45429CRITICAL9.8In the Tenda ac9 v1.0 router with firmware V15.03.05.14_multi, there is a stack overflow vulnerability in /goform/WifiWp...
CVE-2025-32969CRITICAL9.8XWiki is a generic wiki platform. In versions starting from 1.8 and prior to 15.10.16, 16.4.6, and 16.10.1, it is possib...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now