2025 CVE Vulnerabilities

45,296 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-26268MEDIUM6.5DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted...
CVE-2025-25455HIGH7.5Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanMTU2.
CVE-2025-25454HIGH7.5Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanSpeed2.
CVE-2025-32415HIGH7.5In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer un...
CVE-2025-2947CRITICAL9.8IBM i 7.6  contains a privilege escalation vulnerability due to incorrect profile swapping in an OS command.  A malicio...
CVE-2025-29662CRITICAL9.8A RCE vulnerability in the core application in LandChat 3.25.12.18 allows an unauthenticated attacker to execute system ...
CVE-2025-29661HIGH7.2Litepubl CMS <= 7.0.9 is vulnerable to RCE in admin/service/run.
CVE-2025-29181HIGH7.2FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php.
CVE-2025-29180HIGH7.2In FOXCMS <=1.25, the installdb.php file has a time - based blind SQL injection vulnerability. The url_prefix, domain, a...
CVE-2025-29039HIGH7.2An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x41dda8
CVE-2025-43015MEDIUM6.5In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces
CVE-2025-43014MEDIUM6.5In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation
CVE-2025-43013HIGH7.5In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible
CVE-2025-43012CRITICAL9.8In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible
CVE-2025-42921MEDIUM6.5In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin
CVE-2025-39596CRITICAL9.8Weak Authentication vulnerability in Quentn.com GmbH Quentn WP quentn-wp allows Privilege Escalation.This issue affects ...
CVE-2025-39595CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Quentn.com GmbH Qu...
CVE-2025-39594HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Arigato Autore...
CVE-2025-39588CRITICAL9.8Deserialization of Untrusted Data vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allow...
CVE-2025-39587CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix Cost Calc...
CVE-2025-39586HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileG...
CVE-2025-39583HIGH7.1Missing Authorization vulnerability in Bertha AI – Andrew Palmer BERTHA AI bertha-ai-free allows Exploiting Incorrectly ...
CVE-2025-39580MEDIUM5.8Missing Authorization vulnerability in jidaikobo Dashi dashi allows Accessing Functionality Not Properly Constrained by ...
CVE-2025-39569HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in taskbuilder Taskbu...
CVE-2025-39568HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Arture B.V. StoreContrl ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now