2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-60334HIGH7.5TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the ssid parameter in the setWiFiBa...
CVE-2025-60333HIGH7.5TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the wepkey2 parameter in the setWiF...
CVE-2025-40780HIGH8.6In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible f...
CVE-2025-40778HIGH8.6Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject for...
CVE-2025-62606HIGH8.8my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to ...
CVE-2025-62604HIGH7.5MeterSphere is an open source continuous testing platform. Prior to version 2.10.25-lts, a logic flaw allows retrieval o...
CVE-2025-62526HIGH7.8OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, ubusd contains a heap ...
CVE-2025-62525HIGH8.8OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, local users could read...
CVE-2025-62054HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-62029HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-62022HIGH7.5Missing Authorization vulnerability in BuddyPress BuddyPress buddypress.This issue affects BuddyPress: from n/a through ...
CVE-2025-62020HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Infomaniak Network...
CVE-2025-62015HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Josh Kohlbach Adva...
CVE-2025-62008HIGH8.8Deserialization of Untrusted Data vulnerability in acowebs Product Table For WooCommerce product-table-for-woocommerce.T...
CVE-2025-62007HIGH8.8Incorrect Privilege Assignment vulnerability in bPlugins Voice Feedback voice-feedback allows Privilege Escalation.This ...
CVE-2025-62005HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships all...
CVE-2025-60332HIGH7.5A NULL pointer dereference in the SetWLanRadioSettings function of D-Link DIR-823G A1 v1.0.2B05 allows attackers to caus...
CVE-2025-60331HIGH7.5D-Link DIR-823G A1 v1.0.2B05 was discovered to contain a buffer overflow in the FillMacCloneMac parameter in the /EXCU_S...
CVE-2025-60246HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weissmike Simple F...
CVE-2025-60234HIGH8.8Deserialization of Untrusted Data vulnerability in designthemes Single Property single-property allows Object Injection....
CVE-2025-60228HIGH8.8Deserialization of Untrusted Data vulnerability in designthemes Knowledge Base kbase allows Object Injection.This issue ...
CVE-2025-60227HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThimPress WP Pipes wp-pi...
CVE-2025-60222HIGH8.8Incorrect Privilege Assignment vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows...
CVE-2025-60217HIGH7.7Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ypromo PT Luxa Addons pt...
CVE-2025-60215HIGH8.8Deserialization of Untrusted Data vulnerability in designthemes Kriya kriya allows Object Injection.This issue affects K...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now