2025 CVE Vulnerabilities

45,296 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-29625HIGH7.8A buffer overflow vulnerability in Astrolog v7.70 allows attackers to execute arbitrary code or cause a Denial of Servic...
CVE-2025-29209CRITICAL9.8TOTOLINK X18 v9.1.0cu.2024_B20220329 has an unauthorized arbitrary command execution in the enable parameter' of the sub...
CVE-2025-28232CRITICAL9.1Incorrect access control in the HOME.php endpoint of JMBroadcast JMB0150 Firmware v1.0 allows attackers to access the Ad...
CVE-2025-28230CRITICAL9.1Incorrect access control in JMBroadcast JMB0150 Firmware v1.0 allows attackers to access hardcoded administrator credent...
CVE-2025-28229CRITICAL9.8Incorrect access control in Orban OPTIMOD 5950 Firmware v1.0.0.2 and System v2.2.15 allows attackers to bypass authentic...
CVE-2025-28228HIGH7.5A credential exposure vulnerability in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01.09, v01.08, v01.07, and...
CVE-2025-40364HIGH7.8In the Linux kernel, the following vulnerability has been resolved: io_uring: fix io_req_prep_async with provided buffe...
CVE-2025-3790MEDIUM6.9A vulnerability classified as critical has been found in baseweb JSite 1.0. This affects an unknown part of the file /dr...
CVE-2025-3789MEDIUM5.4A vulnerability was found in baseweb JSite 1.0. It has been rated as problematic. Affected by this issue is some unknown...
CVE-2025-32790MEDIUM4.3Dify is an open-source LLM app development platform. In versions 0.6.8 and prior, a vulnerability was identified in the ...
CVE-2025-3788MEDIUM5.4A vulnerability was found in baseweb JSite 1.0. It has been declared as problematic. Affected by this vulnerability is a...
CVE-2025-3787MEDIUM6.5A vulnerability was found in PbootCMS 3.2.5. It has been classified as problematic. Affected is an unknown function of t...
CVE-2025-3106MEDIUM6.4The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
CVE-2025-3786HIGH8.8A vulnerability was found in Tenda AC15 up to 15.03.05.19 and classified as critical. This issue affects the function fr...
CVE-2025-3785HIGH8.8A vulnerability has been found in D-Link DWR-M961 1.1.36 and classified as critical. This vulnerability affects unknown ...
CVE-2025-3056MEDIUM5.4The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versi...
CVE-2025-2492CRITICAL9.2An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted req...
CVE-2025-40325MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: md/raid10: wait barrier before returning discard re...
CVE-2025-40114HIGH7.8In the Linux kernel, the following vulnerability has been resolved: iio: light: Add check for array bounds in veml6075_...
CVE-2025-40014HIGH7.8In the Linux kernel, the following vulnerability has been resolved: objtool, spi: amd: Fix out-of-bounds stack access i...
CVE-2025-39989MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: x86/mce: use is_copy_from_user() to determine copy-...
CVE-2025-39930MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ASoC: simple-card-utils: Don't use __free(device_no...
CVE-2025-39778HIGH7.1In the Linux kernel, the following vulnerability has been resolved: objtool, nvmet: Fix out-of-bounds stack access in n...
CVE-2025-39755MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: staging: gpib: Fix cb7210 pcmcia Oops The pcmcia_...
CVE-2025-39735HIGH7.1In the Linux kernel, the following vulnerability has been resolved: jfs: fix slab-out-of-bounds read in ea_get() Durin...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now