2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-50950HIGH7.5Audiofile v0.3.7 was discovered to contain a NULL pointer dereference via the ModuleState::setup function.
CVE-2025-61136HIGH7.1A Host Header Injection vulnerability in the password reset component in axewater sharewarez v2.4.3 allows remote attack...
CVE-2025-61132HIGH7.1A Host Header Injection vulnerability in the password reset component in levlaz braindump v0.4.14 allows remote attacker...
CVE-2025-62399HIGH7.5Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, makin...
CVE-2025-12105HIGH7.5A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-base...
CVE-2025-10914HIGH7.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Soft...
CVE-2025-61865HIGH8.4Multiple NAS management applications provided by I-O DATA DEVICE, INC. register Windows services with unquoted file path...
CVE-2025-11575HIGH8.8Incorrect Default Permissions vulnerability in MongoDB Atlas SQL ODBC driver on Windows allows Privilege Escalation.This...
CVE-2025-62708HIGH7.5pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability...
CVE-2025-62707HIGH7.5pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability...
CVE-2025-62617HIGH7.2Admidio is an open-source user management solution. Prior to version 4.3.17, an authenticated SQL injection vulnerabilit...
CVE-2025-62614HIGH8.7BookLore is a self-hosted web app for organizing and managing personal book collections. In versions 1.8.1 and prior, an...
CVE-2025-62611HIGH8.2aiomysql is a library for accessing a MySQL database from the asyncio. Prior to version 0.3.0, the client-side settings ...
CVE-2025-62610HIGH8.1Hono is a Web application framework that provides support for any JavaScript runtime. In versions from 1.1.0 to before 4...
CVE-2025-62513HIGH7.5OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log expe...
CVE-2025-60343HIGH7.5Multiple buffer overflows in the AdvSetMacMtuWan function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial ...
CVE-2025-60342HIGH7.5Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the addressNat function. ...
CVE-2025-60341HIGH7.5Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the ssid parameter in the fast_setting_wifi_set...
CVE-2025-60340HIGH7.5Multiple buffer overflows in the SetClientState function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial o...
CVE-2025-60339HIGH7.5Multiple buffer overflow vulnerabilities in the openSchedWifi function of Tenda AC6 v.15.03.06.50 allows attackers to ca...
CVE-2025-60337HIGH7.5Tenda AC6 V2.0 15.03.06.50 was discovered to contain a buffer overflow in the speed_dir parameter in the SetSpeedWan fun...
CVE-2025-60336HIGH7.5A NULL pointer dereference in the sub_41773C function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to caus...
CVE-2025-8677HIGH7.5Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaust...
CVE-2025-60338HIGH7.5Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the DhcpListClient functi...
CVE-2025-60335HIGH7.5A NULL pointer dereference in the main function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a De...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now