2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-8850HIGH8.8In danny-avila/librechat version 0.7.9, there is an insecure API design issue in the 2-Factor Authentication (2FA) flow....
CVE-2025-63423HIGH7.5Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 was discovered to store the Administrator passw...
CVE-2025-61498HIGH7.5A buffer overflow in the UPnP service of Tenda AC8 Hardware v03.03.10.01 allows attackers to cause a Denial of Service (...
CVE-2025-61141HIGH7.5sqls-server/sqls 0.2.28 is vulnerable to command injection in the config command because the openEditor function passes ...
CVE-2025-3355HIGH7.5IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on t...
CVE-2025-63422HIGH7.5Incorrect access control in the Web management interface in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRou...
CVE-2025-63298HIGH8.2A path traversal vulnerability was identified in SourceCodester Pet Grooming Management System 1.0, affecting the admin/...
CVE-2025-36137HIGH7.2IBM Sterling Connect Direct for Unix 6.2.0.7 through 6.2.0.9 iFix004, 6.4.0.0 through 6.4.0.2 iFix001, and 6.3.0.2 throu...
CVE-2025-64112HIGH8Statmatic is a Laravel and Git powered content management system (CMS). Stored XSS vulnerabilities in Collections and Ta...
CVE-2025-64096HIGH8.8CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL...
CVE-2025-62795HIGH7.1JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.21-lts ...
CVE-2025-62726HIGH8.8n8n is an open source workflow automation platform. Prior to 1.113.0, a remote code execution vulnerability exists in th...
CVE-2025-61196HIGH8.8An issue in BusinessNext CRMnext v.10.8.3.0 allows a remote attacker to execute arbitrary code via the comments input pa...
CVE-2025-61121HIGH7.5Mobile Scanner Android App version 2.12.38 (package name com.glority.everlens), developed by Glority Global Group Ltd., ...
CVE-2025-61120HIGH7.5AG Life Logger Android App version v1.0.2.72 and before (package name com.donki.healthy), developed by IO FIT, K.K., con...
CVE-2025-61119HIGH7.5Kanova Android App version 1.0.27 (package name com.karelane), developed by Karely L.L.C., contains improper access cont...
CVE-2025-61114HIGH7.52nd Line Android App version v1.2.92 and before (package name com.mysecondline.app), developed by AutoBizLine, Inc., con...
CVE-2025-12060HIGH8.9The keras.utils.get_file API in Keras, when used with the extract=True option for tar archives, is vulnerable to a path ...
CVE-2025-62712HIGH8.1JumpServer is an open source bastion host and an operation and maintenance security audit system. In JumpServer versions...
CVE-2025-61118HIGH7.5mCarFix Motorists App version 2.3 (package name com.skytop.mcarfix), developed by Paniel Mwaura, contains improper acces...
CVE-2025-61117HIGH7.5Senza: Keto & Fasting Android App version 2.10.15 (package name com.gl.senza), developed by Paul Itoi, contains an impro...
CVE-2025-61116HIGH7.5AdForest - Classified Android App version 4.0.12 (package name scriptsbundle.adforest), developed by Muhammad Jawad Arsh...
CVE-2025-61115HIGH7.5ABC Fine Wine & Spirits Android App version v.11.27.5 and before (package name com.cta.abcfinewineandspirits), developed...
CVE-2025-61113HIGH7.5TalkTalk 3.3.6 Android App contains improper access control vulnerabilities in multiple API endpoints. By modifying requ...
CVE-2025-46423HIGH7.8Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now