2025 CVE Vulnerabilities

45,152 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-69284MEDIUM4.3Plane is an an open-source project management tool. In plane.io, a guest user doesn't have a permission to access https[...
CVE-2025-67269HIGH7.5An integer underflow vulnerability exists in the `nextstate()` function in `gpsd/packet.c` of gpsd versions prior to com...
CVE-2025-67268CRITICAL9.8gpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/driver_nmea2000.c file...
CVE-2025-62852MEDIUM6.5A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker...
CVE-2025-62842HIGH7.8An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attac...
CVE-2025-62840LOW3.3A generation of error message containing sensitive information vulnerability has been reported to affect HBS 3 Hybrid Ba...
CVE-2025-59389CRITICAL9.8An SQL injection vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit t...
CVE-2025-59387HIGH8.1An SQL injection vulnerability has been reported to affect MARS (Multi-Application Recovery Service). The remote attacke...
CVE-2025-59384HIGH7.5A path traversal vulnerability has been reported to affect Qfiling. The remote attackers can then exploit the vulnerabil...
CVE-2025-59381MEDIUM4.9A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker ...
CVE-2025-59380MEDIUM4.9A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker ...
CVE-2025-53597MEDIUM6.5A buffer overflow vulnerability has been reported to affect License Center. If a remote attacker gains an administrator ...
CVE-2025-53594MEDIUM4.4A path traversal vulnerability has been reported to affect several product versions. If a local attacker gains a user ac...
CVE-2025-52871MEDIUM6.5An out-of-bounds read vulnerability has been reported to affect License Center. If a remote attacker gains a user accoun...
CVE-2025-48721MEDIUM6.5A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker...
CVE-2025-11837CRITICAL9.8An improper control of generation of code vulnerability has been reported to affect Malware Remover. The remote attacker...
CVE-2025-65125CRITICAL9.8SQL injection in gosaliajainam/online-movie-booking 5.5 in movie_details.php allows attackers to gain sensitive informat...
CVE-2025-62857MEDIUM6.1A cross-site scripting (XSS) vulnerability has been reported to affect QuMagie. The remote attackers can then exploit th...
CVE-2025-57705MEDIUM4.9An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating...
CVE-2025-54166MEDIUM4.9An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote atta...
CVE-2025-54165MEDIUM4.9An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote atta...
CVE-2025-54164MEDIUM4.9An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote atta...
CVE-2025-53596MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...
CVE-2025-53593MEDIUM6.5A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker...
CVE-2025-53592MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now