2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-63464HIGH7.5Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_42396...
CVE-2025-63463HIGH7.5Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the wifiOff parameter in the sub_42...
CVE-2025-63462HIGH7.5Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the wifiOff parameter in the sub_4...
CVE-2025-63461HIGH7.5Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the urldec...
CVE-2025-63460HIGH7.5Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_42...
CVE-2025-63469HIGH7.5Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_421BA...
CVE-2025-63468HIGH7.5Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the sub_...
CVE-2025-63467HIGH7.5Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_42540...
CVE-2025-63466HIGH7.5Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the sub_4...
CVE-2025-12509HIGH8.4On a client with an admin user, a Global_Shipping script can be implemented. The script could later be executed on the B...
CVE-2025-12508HIGH8.4When using domain users as BRAIN2 users, communication with Active Directory services is unencrypted. This can lead to t...
CVE-2025-12507HIGH8.8The service Bizerba Communication Server (BCS) has an unquoted service path. Due to the way Windows searches the executa...
CVE-2025-64389HIGH8.3The web server of the device performs exchanges of sensitive information in clear text through an insecure protocol.
CVE-2025-64168HIGH7.1Agno is a multi-agent framework, runtime and control plane. From 2.0.0 to before 2.2.2, under high concurrency, when ses...
CVE-2025-60749HIGH7.8DLL Hijacking vulnerability in Trimble SketchUp desktop 2025 via crafted libcef.dll used by sketchup_webhelper.exe.
CVE-2025-57107HIGH7.1Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader...
CVE-2025-57106HIGH7.5Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerabi...
CVE-2025-12501HIGH7.5Integer overflow in GameMaker IDE below 2024.14.0 version can lead to can lead to application crashes through denial-of-...
CVE-2025-64386HIGH7.7The equipment grants a JWT token for each connection in the timeline, but during an active valid session, a hijacking of...
CVE-2025-33003HIGH7.8IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a non-root user to gain higher privileges/capabi...
CVE-2025-64366HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStu...
CVE-2025-64364HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-64363HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-64360HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-64359HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now