2025 CVE Vulnerabilities

45,144 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-13190HIGH8.8A vulnerability was found in D-Link DIR-816L 2_06_b09_beta. This vulnerability affects the function scandir_main of the ...
CVE-2025-9317HIGH8.4The vulnerability, if exploited, could allow a miscreant with read access to Edge Project files or Edge Offline Cache f...
CVE-2025-8386HIGH7.2The vulnerability, if exploited, could allow an authenticated miscreant (with privilege of "aaConfigTools") to tamper w...
CVE-2025-64309HIGH7.4The affected product discloses device telemetry, configuration, and sensitive information via WebSocket traffic to unaut...
CVE-2025-64308HIGH7.1The Brightpick Mission Control web application exposes hardcoded credentials in its client-side JavaScript bundle to Bri...
CVE-2025-64307HIGH7.1The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized...
CVE-2025-62765HIGH8.7General Industrial Controls Lynx+ Gateway is vulnerable to a cleartext transmission vulnerability that could allow an a...
CVE-2025-59780HIGH8.7General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could all...
CVE-2025-55034HIGH8.8General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requirement vulnerability, which may allow a...
CVE-2025-13187HIGH7.5A security vulnerability has been detected in Intelbras ICIP 2.0.20. Affected is an unknown function of the file /xml/si...
CVE-2025-63891HIGH7.5Information Disclosure in web-accessible backup file in SourceCodester Simple Online Book Store System allows a remote u...
CVE-2025-13185HIGH7.2A security flaw has been discovered in Bdtask/CodeCanyon News365 up to 7.0.3. This affects an unknown function of the fi...
CVE-2025-13033HIGH7.5A vulnerability was identified in the email parsing library due to improper handling of specially formatted recipient em...
CVE-2025-63680HIGH8.6Nero BackItUp in the Nero Productline is vulnerable to a path parsing/UI rendering flaw (CWE-22) that, in combination wi...
CVE-2025-13177HIGH8.8A vulnerability was detected in Bdtask/CodeCanyon SalesERP up to 20250728. This affects an unknown part. The manipulatio...
CVE-2025-54346HIGH7.6A Reflected Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert vers...
CVE-2025-54345HIGH7.5An issue was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. Sensitive Informati...
CVE-2025-13172HIGH8.8A security flaw has been discovered in CodeAstro Gym Management System 1.0. Affected is an unknown function of the file ...
CVE-2025-13171HIGH8.8A vulnerability was identified in ZZCMS 2023. This impacts an unknown function of the file /admin/wangkan_list.php. Such...
CVE-2025-13204HIGH7.3npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use ...
CVE-2025-9982HIGH7.5A vulnerability exists in QuickCMS version 6.8 where sensitive admin credentials are hardcoded in a configuration file a...
CVE-2025-11918HIGH7.3Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the...
CVE-2025-8855HIGH8.1Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authenticatio...
CVE-2025-55070HIGH7.5Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticate...
CVE-2025-64444HIGH8.6Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in NCP-HG100 1.4...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now