2025 CVE Vulnerabilities

45,124 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-31936HIGH7Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) ...
CVE-2025-31356MEDIUM5.6Insufficient verification of data authenticity for some Intel(R) Trust Domain Extensions (Intel(R) TDX) within Ring 0: H...
CVE-2025-0041MEDIUM4.6Uncontrolled search paths in the Vitis™ Embedded Single File Download (SFD) for local Windows installation could allow a...
CVE-2025-31114CRITICAL9.3Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code ex...
CVE-2025-30241HIGH8.6Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input pro...
CVE-2025-30240MEDIUM5.1The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By ...
CVE-2025-30239HIGH8.5In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive co...
CVE-2025-30238HIGH8.6In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to e...
CVE-2025-30237HIGH8.7The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not c...
CVE-2025-32736MEDIUM4.9Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may all...
CVE-2025-15683HIGH8.8TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial-of-service vulnerabilities in its web server. An ...
CVE-2025-15682HIGH8.7TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exhaustion vulnerability in its web server. An unauth...
CVE-2025-15681CRITICAL9.2TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authentic...
CVE-2025-15680LOW2.4TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without sufficient protection. A ph...
CVE-2025-13294CRITICAL9.3An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP ...
CVE-2025-13293CRITICAL9.3A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attack...
CVE-2025-4438Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-71413MEDIUM6Malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers cause repeated resets w...
CVE-2025-71412HIGH7.1Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion...
CVE-2025-71411MEDIUM6Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic c...
CVE-2025-71410MEDIUM6Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and...
CVE-2025-71409HIGH7.1Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages ...
CVE-2025-63235HIGH7.5In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CON...
CVE-2025-6508MEDIUM4.3The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to b...
CVE-2025-15674LOW2.7The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now