2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-69766CRITICAL9.8Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handl...
CVE-2025-69763CRITICAL9.8Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the vlanId parameter, which can cause memor...
CVE-2025-69762CRITICAL9.8Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the list parameter, which can cause memory ...
CVE-2025-66960HIGH7.5An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function rea...
CVE-2025-66959HIGH7.5An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder
CVE-2025-70648HIGH7.5Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow in the security_5g parameter of the sub_727F4 function....
CVE-2025-70646HIGH7.5Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow in the security parameter of the sub_72290 function. Th...
CVE-2025-70644HIGH7.5Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the time parameter of the sub_60CFC function. This ...
CVE-2025-57681MEDIUM5.4The WorklogPRO - Timesheets for Jira plugin in Jira Data Center before version 4.23.6-jira10 and before version 4.23.5-j...
CVE-2025-70651HIGH7.5Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow in the ssid parameter of the form_fast_setting_wifi_se...
CVE-2025-70650HIGH7.5Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the deviceList parameter of the formSetMacFilterCfg...
CVE-2025-70645HIGH7.5Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the deviceList parameter of the formSetWifiMacFilte...
CVE-2025-13878HIGH7.5Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 thro...
CVE-2025-14083LOW2.7A flaw was found in the Keycloak Admin REST API. This vulnerability allows the exposure of backend schema and rules, pot...
CVE-2025-14559MEDIUM6.5A flaw was found in the keycloak-services component of Keycloak. This vulnerability allows the issuance of access and re...
CVE-2025-68133HIGH7.4EVerest is an EV charging software stack. In versions 2025.9.0 and below, an attacker can exhaust the operating system's...
CVE-2025-15521CRITICAL9.8The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege e...
CVE-2025-58744HIGH7.5Use of Default Credentials, Hard-coded Credentials vulnerability in C2SGlobalSettings.dll in Milner ImageDirector Cap...
CVE-2025-58743HIGH7.5Use of a Broken or Risky Cryptographic Algorithm (DES) vulnerability in the Password class in C2SConnections.dll in Mi...
CVE-2025-58742MEDIUM5.9Insufficiently Protected Credentials, Improper Restriction of Communication Channel to Intended Endpoints vulnerability ...
CVE-2025-58741HIGH7.5Insufficiently Protected Credentials vulnerability in the Credential Field of Milner ImageDirector Capture allows retrie...
CVE-2025-58740MEDIUM5.5The use of a hard-coded encryption key in calls to the Password function in C2SGlobalSettings.dll in Milner ImageDirecto...
CVE-2025-15367MEDIUM5.9The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigati...
CVE-2025-15366MEDIUM5.9The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigat...
CVE-2025-15282MEDIUM6User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now