2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-60672MEDIUM6.5An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vuln...
CVE-2025-60701MEDIUM6.5A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` a...
CVE-2025-60700MEDIUM6.5A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` a...
CVE-2025-60693MEDIUM6.5A stack-based buffer overflow exists in the get_merge_mac function of the httpd binary on Linksys E1200 v2 routers (Firm...
CVE-2025-60671MEDIUM5.4A command injection vulnerability exists in the D-Link DIR-823G router firmware DIR823G_V1.0.2B05_20181207.bin in the ti...
CVE-2025-59480MEDIUM6.5Mattermost Mobile Apps versions <=2.32.0 fail to verify that SSO redirect tokens originate from the trusted server, whic...
CVE-2025-12784MEDIUM4.9Certain HP LaserJet Pro printers may be vulnerable to information disclosure leading to credential exposure by altering ...
CVE-2025-11777MEDIUM4.3Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to properly validate team membership permissions in the A...
CVE-2025-60695MEDIUM5.9A stack-based buffer overflow vulnerability exists in the mtk_dut binary of Linksys E7350 routers (Firmware 1.1.00.032)....
CVE-2025-20355MEDIUM4.7A vulnerability in the web-based management interface of Cisco Catalyst Center Virtual Appliance could allow an unauthen...
CVE-2025-20353MEDIUM6.1A vulnerability in the web-based management interface of Cisco Catalyst Center could allow an unauthenticated, remote at...
CVE-2025-20346MEDIUM4.3A vulnerability in Cisco Catalyst Center could allow an authenticated, remote attacker to execute operations that should...
CVE-2025-11538MEDIUM6.8A vulnerability exists in Keycloak's server distribution where enabling debug mode (--debug <port>) insecurely defaults ...
CVE-2025-64718MEDIUM5.3js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to mod...
CVE-2025-64714MEDIUM5.8PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Starting in version 1.7.7 and prior...
CVE-2025-64703MEDIUM6.5MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can get sensitive informations b...
CVE-2025-64525MEDIUM6.5Astro is a web framework. In Astro versions 2.16.0 up to but excluding 5.15.5 which utilizeon-demand rendering, request ...
CVE-2025-60689MEDIUM5.4An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200...
CVE-2025-60688MEDIUM6.5A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681...
CVE-2025-60687MEDIUM6.5An unauthenticated command injection vulnerability exists in the ToToLink LR1200GB Router firmware V9.1.0u.6619_B2023013...
CVE-2025-60686MEDIUM5.1A local stack-based buffer overflow vulnerability exists in the infostat.cgi and cstecgi.cgi binaries of ToToLink router...
CVE-2025-60685MEDIUM5.1A stack buffer overflow exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary (s...
CVE-2025-60684MEDIUM6.5A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681...
CVE-2025-60683MEDIUM6.5A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf...
CVE-2025-60682MEDIUM6.5A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the cloudup...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now