2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-65368MEDIUM6.1SparkyFitness v0.15.8.2 is vulnerable to Cross Site Scripting (XSS) via user input and LLM output.
CVE-2025-60011MEDIUM6.9An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Ne...
CVE-2025-60007MEDIUM6.8A NULL Pointer Dereference vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS on MX, SRX and EX...
CVE-2025-60003HIGH8.7A Buffer Over-read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved ...
CVE-2025-59961MEDIUM6.8An Incorrect Permission Assignment for Critical Resource vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Ne...
CVE-2025-59960HIGH7.4An Improper Check for Unusual or Exceptional Conditions vulnerability in the Juniper DHCP service (jdhcpd) of Juniper Ne...
CVE-2025-59959MEDIUM6.8An Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Jun...
CVE-2025-52987MEDIUM6.1A clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insig...
CVE-2025-65349MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability in Web management interface in Each Italy Wireless Mini Router WIRELES...
CVE-2025-15265MEDIUM6.1An SSR XSS exists in async hydration when attacker‑controlled keys are passed to hydratable. The key is embedded inside ...
CVE-2025-70303MEDIUM5.5A heap overflow in the uncv_parse_config() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) v...
CVE-2025-70302MEDIUM5.5A heap overflow in the ghi_dmx_declare_opid_bin() function of GPAC v2.4.0 allows attackers to cause a Denial of Service ...
CVE-2025-67647CRITICAL9.1SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.49.5, Svelt...
CVE-2025-13845HIGH7.8CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious pro...
CVE-2025-13844MEDIUM5.3CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious ...
CVE-2025-9014HIGH7.5A Null Pointer Dereference vulnerability exists in the referer header check of the web portal of TP-Link TL-WR841N v14, ...
CVE-2025-70307HIGH7.5A stack overflow in the dump_ttxt_sample function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via...
CVE-2025-70299MEDIUM6.5A heap overflow in the avi_parse_input_file() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS...
CVE-2025-36911HIGH7.1In key-based pairing, there is a possible ID due to a logic error in the code. This could lead to remote (proximal/adjac...
CVE-2025-70656HIGH7.5Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the mac parameter of the sub_65B5C function. This v...
CVE-2025-70310MEDIUM5.5A heap overflow in the vorbis_to_intern() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) vi...
CVE-2025-70309MEDIUM5.5A stack overflow in the pcmreframe_flush_packet function of GPAC v2.4.0 allows attackers to cause a Denial of Service (D...
CVE-2025-70308HIGH7.5An out-of-bounds read in the GSF demuxer filter component of GPAC v2.4.0 allows attackers to cause a Denial of Service (...
CVE-2025-70305MEDIUM5.5A stack overflow in the dmx_saf function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafte...
CVE-2025-70304HIGH7.5A buffer overflow in the vobsub_get_subpic_duration() function of GPAC v2.4.0 allows attackers to cause a Denial of Serv...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now