2025 CVE Vulnerabilities

45,296 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-33026HIGH7.8In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass...
CVE-2025-29705MEDIUM4.3code-gen <=2.0.6 is vulnerable to Incorrect Access Control. The project does not have permission control allowing anyone...
CVE-2025-28100CRITICAL9.8A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the co...
CVE-2025-32780HIGH7.3BleachBit cleans files to free disk space and to maintain privacy. BleachBit for Windows up to version 4.6.2 is vulnerab...
CVE-2025-32779MEDIUM6.5E.D.D.I (Enhanced Dialog Driven Interface) is a middleware to connect and manage LLM API bots. In versions before 5.5.0,...
CVE-2025-32776MEDIUM5.5OpenRazer is an open source driver and user-space daemon to control Razer device lighting and other features on GNU/Linu...
CVE-2025-29817MEDIUM5.7Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network.
CVE-2025-32911CRITICAL9A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function...
CVE-2025-28198MEDIUM5.9A SQL injection vulnerability in Hitout car sale 1.0 allows a remote attacker to obtain sensitive information via the or...
CVE-2025-24949MEDIUM6.5In JotUrl 2.0, is possible to bypass security requirements during the password change process.
CVE-2025-24948MEDIUM6.5In JotUrl 2.0, passwords are sent via HTTP GET-type requests, potentially exposing credentials to eavesdropping or insec...
CVE-2025-3523MEDIUM6.4When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only t...
CVE-2025-3522MEDIUM6.3Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally....
CVE-2025-32949MEDIUM6.5This vulnerability allows any authenticated user to cause the server to consume very large amounts of disk space when ex...
CVE-2025-32948HIGH7.5The vulnerability allows any attacker to cause the PeerTube server to stop functioning, or in special cases send request...
CVE-2025-32947HIGH7.5This vulnerability allows any attacker to cause the PeerTube server to stop responding to requests due to an infinite lo...
CVE-2025-2830MEDIUM6.3By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into inclu...
CVE-2025-29281HIGH8.8In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component...
CVE-2025-28145MEDIUM6.5Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerab...
CVE-2025-28144MEDIUM6.5Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a stack overflow vlunerabili...
CVE-2025-28143MEDIUM6.5Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerab...
CVE-2025-28142MEDIUM6.5Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerab...
CVE-2025-27980MEDIUM6.5cashbook v4.0.3 has an arbitrary file read vulnerability in /api/entry/flow/invoice/show?invoice=.
CVE-2025-29280MEDIUM4.8Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system ...
CVE-2025-28137CRITICAL9.8The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in th...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now