2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-60698HIGH7.3A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` a...
CVE-2025-60697HIGH7.3A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` a...
CVE-2025-12785HIGH7.5Certain HP LaserJet Pro printers may be vulnerable to information disclosure leading to credential exposure by altering ...
CVE-2025-60696HIGH8.4A stack-based buffer overflow vulnerability exists in the makeRequest.cgi binary of Linksys RE7000 routers (Firmware FW_...
CVE-2025-60694HIGH7.5A stack-based buffer overflow exists in the validate_static_route function of the httpd binary on Linksys E1200 v2 route...
CVE-2025-60692HIGH8.4A stack-based buffer overflow vulnerability exists in the libshared.so library of Cisco Linksys E1200 v2 routers (Firmwa...
CVE-2025-60691HIGH8.8A stack-based buffer overflow exists in the httpd binary of Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar....
CVE-2025-60690HIGH8.8A stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (F...
CVE-2025-20349HIGH8.8A vulnerability in the REST API of Cisco Catalyst Center could allow an authenticated, remote attacker to execute arbitr...
CVE-2025-20341HIGH8.8A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate priv...
CVE-2025-13121HIGH7.3A security vulnerability has been detected in cameasy Liketea 1.0.0. Impacted is the function list of the file laravel/a...
CVE-2025-64511HIGH8.8MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can access internal network serv...
CVE-2025-64740HIGH7.8Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an...
CVE-2025-64739HIGH7.5External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure ...
CVE-2025-62483HIGH7.5Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated use...
CVE-2025-12765HIGH7.4pgAdmin <= 9.9  is affected by a vulnerability in the LDAP authentication mechanism allows bypassing TLS certificate ver...
CVE-2025-12764HIGH7.5pgAdmin <= 9.9  is affected by an LDAP injection vulnerability in the LDAP authentication flow that allows an attacker t...
CVE-2025-12763HIGH8.8pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused ...
CVE-2025-12844HIGH7.1The AI Engine plugin for WordPress is vulnerable to PHP Object Injection via PHAR Deserialization in all versions up to,...
CVE-2025-12733HIGH8.8The Import any XML, CSV or Excel File to WordPress (WP All Import) plugin for WordPress is vulnerable to Remote Code Exe...
CVE-2025-11923HIGH8.8The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to privilege escalati...
CVE-2025-64523HIGH8.8File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ...
CVE-2025-64500HIGH7.3Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundati...
CVE-2025-40206HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_objref: validate objref and objrefma...
CVE-2025-40205HIGH7.8In the Linux kernel, the following vulnerability has been resolved: btrfs: avoid potential out-of-bounds in btrfs_encod...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now