2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-10693HIGH7.6When SmartStart Inclusion fails during the onboarding of a Z-Wave PIR sensor, the sensor will join the network as a non-...
CVE-2025-64349HIGH8.8ELOG allows an authenticated user to modify another user's profile. An attacker can edit a target user's email address, ...
CVE-2025-64348HIGH7.1ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service. If the ...
CVE-2025-63458HIGH7.5Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the timeZone parameter in the form_fast_setting_wi...
CVE-2025-63454HIGH7.5Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow via the deviceId parameter in the get_parentContro...
CVE-2025-62618HIGH8.6ELOG allows an authenticated user to upload arbitrary HTML files. The HTML content is executed in the context of other u...
CVE-2025-12547HIGH8.1A vulnerability was identified in LogicalDOC Community Edition up to 9.2.1. This vulnerability affects unknown code of t...
CVE-2025-63459HIGH7.5Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_42...
CVE-2025-63465HIGH7.5Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_42288...
CVE-2025-63464HIGH7.5Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_42396...
CVE-2025-63463HIGH7.5Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the wifiOff parameter in the sub_42...
CVE-2025-63462HIGH7.5Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the wifiOff parameter in the sub_4...
CVE-2025-63461HIGH7.5Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the urldec...
CVE-2025-63460HIGH7.5Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_42...
CVE-2025-63469HIGH7.5Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_421BA...
CVE-2025-63468HIGH7.5Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the sub_...
CVE-2025-63467HIGH7.5Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_42540...
CVE-2025-63466HIGH7.5Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the sub_4...
CVE-2025-12509HIGH8.4On a client with an admin user, a Global_Shipping script can be implemented. The script could later be executed on the B...
CVE-2025-12508HIGH8.4When using domain users as BRAIN2 users, communication with Active Directory services is unencrypted. This can lead to t...
CVE-2025-12507HIGH8.8The service Bizerba Communication Server (BCS) has an unquoted service path. Due to the way Windows searches the executa...
CVE-2025-64389HIGH8.3The web server of the device performs exchanges of sensitive information in clear text through an insecure protocol.
CVE-2025-64168HIGH7.1Agno is a multi-agent framework, runtime and control plane. From 2.0.0 to before 2.2.2, under high concurrency, when ses...
CVE-2025-60749HIGH7.8DLL Hijacking vulnerability in Trimble SketchUp desktop 2025 via crafted libcef.dll used by sketchup_webhelper.exe.
CVE-2025-57107HIGH7.1Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now