2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14058LOW3.2A potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized us...
CVE-2025-13455HIGH7.8A vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to bypass T...
CVE-2025-13454MEDIUM6.8A potential vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user t...
CVE-2025-13453MEDIUM5.1A potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with physical access to read...
CVE-2025-13154MEDIUM6.8An improper link following vulnerability was reported in the SmartPerformanceAddin for Lenovo Vantage that could allow a...
CVE-2025-12533——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-12166HIGH7.5The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to bli...
CVE-2025-71166MEDIUM5.4Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the admi...
CVE-2025-71165MEDIUM5.4Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the admi...
CVE-2025-71164MEDIUM5.4Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the Edit...
CVE-2025-33206HIGH7.8NVIDIA NSIGHT Graphics for Linux contains a vulnerability where an attacker could cause command injection. A successful ...
CVE-2025-14557MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Face...
CVE-2025-14556MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Flag...
CVE-2025-11224MEDIUM5.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.3.6, 18.4 before 18.4.4, and ...
CVE-2025-71021HIGH7.5Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the serverName parameter of the sub_65A28 function....
CVE-2025-70747HIGH7.5Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the serviceName parameter of the sub_65A28 function...
CVE-2025-65397MEDIUM6.8An insecure authentication mechanism in the safe_exec.sh startup script of Blurams Flare Camera version 24.1114.151.929 ...
CVE-2025-63644MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in pH7Software pH7-Social-Dating-CMS 17.9.1 in the user profile...
CVE-2025-70968CRITICAL9.8FreeImage 3.18.0 contains a Use After Free in PluginTARGA.cpp;loadRLE().
CVE-2025-67835MEDIUM6.5Paessler PRTG Network Monitor before 25.4.114 allows Denial-of-Service (DoS) by an authenticated attacker via the Notifi...
CVE-2025-67834MEDIUM5.4Paessler PRTG Network Monitor before 25.4.114 allows XSS by an unauthenticated attacker via the filter parameter.
CVE-2025-67833MEDIUM6.1Paessler PRTG Network Monitor before 25.4.114 allows XSS by an unauthenticated attacker via the tag parameter.
CVE-2025-65396MEDIUM6.1A vulnerability in the boot process of Blurams Flare Camera version 24.1114.151.929 and earlier allows a physically prox...
CVE-2025-37185MEDIUM4.8Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re...
CVE-2025-37184CRITICAL9.8A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-fa...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now