2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-44894 | CRITICAL | 9.8 | 0.5% | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radDftParamKey parameter in the web_radiu... |
| CVE-2025-44891 | CRITICAL | 9.8 | 0.5% | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_v3host_... |
| CVE-2025-44883 | CRITICAL | 9.8 | 0.5% | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the tacIp parameter in the web_tacplus_server... |
| CVE-2025-44882 | CRITICAL | 9.8 | 2.6% | May 20, 2025 | A command injection vulnerability in the component /cgi-bin/firewall.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to ... |
| CVE-2025-44880 | CRITICAL | 9.8 | 2.6% | May 20, 2025 | A command injection vulnerability in the component /cgi-bin/adm.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execu... |
| CVE-2025-44893 | CRITICAL | 9.8 | 0.6% | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ruleNamekey parameter in the web_acl_mgmt... |
| CVE-2025-44890 | CRITICAL | 9.8 | 0.5% | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_notifyv... |
| CVE-2025-44888 | CRITICAL | 9.8 | 0.5% | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the stp_conf_name parameter in the web_stp_gl... |
| CVE-2025-44887 | CRITICAL | 9.8 | 0.5% | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radIpkey parameter in the web_radiusSrv_p... |
| CVE-2025-44886 | CRITICAL | 9.8 | 0.5% | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the byruleEditName parameter in the web_acl_m... |
| CVE-2025-44885 | CRITICAL | 9.8 | 0.5% | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the remote_ip parameter in the web_snmpv3_rem... |
| CVE-2025-44884 | CRITICAL | 9.8 | 0.5% | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the web_sys_infoContact_post function. |
| CVE-2025-44881 | CRITICAL | 9.8 | 2.6% | May 20, 2025 | A command injection vulnerability in the component /cgi-bin/qos.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execu... |
| CVE-2025-47277 | CRITICAL | 9.8 | 0.9% | May 20, 2025 | vLLM, an inference and serving engine for large language models (LLMs), has an issue in versions 0.6.5 through 0.8.4 tha... |
| CVE-2025-46725 | CRITICAL | 9.8 | 0.5% | May 20, 2025 | Langroid is a Python framework to build large language model (LLM)-powered applications. Prior to version 0.53.15, `Lanc... |
| CVE-2025-46724 | CRITICAL | 9.8 | 0.7% | May 20, 2025 | Langroid is a Python framework to build large language model (LLM)-powered applications. Prior to version 0.53.15, `Tabl... |
| CVE-2025-44084 | CRITICAL | 9.8 | 18.1% | May 20, 2025 | D-link DI-8100 16.07.26A1 is vulnerable to Command Injection. An attacker can exploit this vulnerability by crafting spe... |
| CVE-2025-48017 | CRITICAL | 9 | 0.4% | May 20, 2025 | Improper limitation of pathname in Circuit Provisioning and File Import applications allows modification and uploading o... |
| CVE-2025-4978 | CRITICAL | 9.8 | 17.0% | May 20, 2025 | A vulnerability, which was classified as very critical, was found in Netgear DGND3700 1.1.00.15_1.00.15NA. This affects ... |
| CVE-2025-40635 | CRITICAL | 9.3 | 0.3% | May 20, 2025 | SQL injection vulnerability in Comerzzia Backoffice: Sales Orchestrator 3.0.15. This vulnerability allows an attacker to... |
| CVE-2025-40634 | CRITICAL | 9.2 | 0.6% | May 20, 2025 | Stack-based buffer overflow vulnerability in the 'conn-indicator' binary running as root on the TP-Link Archer AX50 rout... |
| CVE-2025-4322 | CRITICAL | 9.8 | 18.2% | May 20, 2025 | The Motors theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and inc... |
| CVE-2025-48340 | CRITICAL | 9.8 | 0.2% | May 19, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Danny Vink User Profile Meta Manager user-profile-meta allows Privile... |
| CVE-2025-39402 | CRITICAL | 9.9 | 0.3% | May 19, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla WPAMS apartment-management allows Upload a Web... |
| CVE-2025-39401 | CRITICAL | 10 | 0.5% | May 19, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla WPAMS apartment-management allows Upload a Web... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now