2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-45790CRITICAL9.8TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the priority parameter in the setMacQos interface of /li...
CVE-2025-45789CRITICAL9.8TOTOLINK A3100R V5.9c.1527 is vulnerable to buffer overflow via the urlKeyword parameter in setParentalRules.
CVE-2025-45788CRITICAL9.8TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the comment parameter in setMacFilterRules.
CVE-2025-45787CRITICAL9.8TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow viathe comment parameter in setIpPortFilterRules.
CVE-2025-0505CRITICAL10On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain ...
CVE-2025-26845CRITICAL9.8An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the configuration file can us...
CVE-2025-45841CRITICAL9.8TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the text parameter...
CVE-2025-26844CRITICAL9.8An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag.
CVE-2025-36546CRITICAL9.2On an F5OS system, if the root user had previously configured the system to allow login via SSH key-based authentication...
CVE-2025-3476CRITICAL9.4Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager. The vulnerability could allows privilege e...
CVE-2025-46828CRITICAL9.8WeGIA is a web manager for charitable institutions. An unauthenticated SQL Injection vulnerability was identified in ve...
CVE-2025-20221CRITICAL9.1A vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote ...
CVE-2025-20188CRITICAL10A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client de...
CVE-2025-47688CRITICAL9.8Missing Authorization vulnerability in Saad Iqbal Advanced File Manager file-manager-advanced allows Exploiting Incorrec...
CVE-2025-47657CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Productive Minds P...
CVE-2025-47635CRITICAL9.8Server-Side Request Forgery (SSRF) vulnerability in WPWebinarSystem WebinarPress wp-webinarsystem allows Server Side Req...
CVE-2025-47548CRITICAL9.8Server-Side Request Forgery (SSRF) vulnerability in Varun Dubey Wbcom Designs - Activity Link Preview For BuddyPress act...
CVE-2025-2777CRITICAL9.8SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the l...
CVE-2025-2776CRITICAL9.8SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the S...
CVE-2025-4104CRITICAL9.8The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on t...
CVE-2025-20968CRITICAL9.1Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 1...
CVE-2025-20967CRITICAL9.1Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 1...
CVE-2025-20949CRITICAL9.1Path traversal vulnerability in Samsung Members prior to version 5.0.00.11 allows attackers to read and write arbitrary ...
CVE-2025-0668CRITICAL9.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Serve...
CVE-2025-32404CRITICAL9.8An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now