2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-61770HIGH7.5Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, `Rack::Multipart::Parser` b...
CVE-2025-11398HIGH8.8A weakness has been identified in SourceCodester Hotel and Lodge Management System 1.0. The impacted element is an unkno...
CVE-2025-59425HIGH7.5vLLM is an inference and serving engine for large language models (LLMs). Before version 0.11.0rc2, the API key support ...
CVE-2025-57564HIGH8.2CubeAPM nightly-2025-08-01-1 allow unauthenticated attackers to inject arbitrary log entries into production systems via...
CVE-2025-54406HIGH8.8Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A...
CVE-2025-54405HIGH8.8Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A...
CVE-2025-54404HIGH8.8Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A spec...
CVE-2025-54403HIGH8.8Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A spec...
CVE-2025-54402HIGH8.8Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b19...
CVE-2025-54401HIGH8.8Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b19...
CVE-2025-54400HIGH8.8Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b19...
CVE-2025-54399HIGH8.8Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b19...
CVE-2025-50505HIGH7.8Clash Verge Rev thru 2.2.3 (fixed in 2.3.0) forces the installation of system services(clash-verge-service) by default a...
CVE-2025-48826HIGH8.8A format string vulnerability exists in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially craf...
CVE-2025-40889HIGH8.1A path traversal vulnerability was discovered in the Time Machine functionality due to missing validation of two input p...
CVE-2025-40886HIGH8.8A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter...
CVE-2025-3719HIGH8.1An access control vulnerability was discovered in the CLI functionality due to a specific access restriction not being p...
CVE-2025-11389HIGH8.8A security flaw has been discovered in Tenda AC15 15.03.05.18. Affected is an unknown function of the file /goform/saveA...
CVE-2025-11388HIGH8.8A vulnerability was identified in Tenda AC15 15.03.05.18. This impacts an unknown function of the file /goform/setNotUpg...
CVE-2025-11387HIGH8.8A vulnerability was determined in Tenda AC15 15.03.05.18. This affects an unknown function of the file /goform/fast_sett...
CVE-2025-11386HIGH8.8A vulnerability was found in Tenda AC15 15.03.05.18. The impacted element is an unknown function of the file /goform/Set...
CVE-2025-11385HIGH8.8A vulnerability has been found in Tenda AC20 up to 16.03.08.12. The affected element is the function sscanf of the file ...
CVE-2025-11359HIGH8.8A security vulnerability has been detected in code-projects Simple Banking System 1.0. The affected element is an unknow...
CVE-2025-11358HIGH8.8A weakness has been identified in code-projects Simple Banking System 1.0. Impacted is an unknown function of the file /...
CVE-2025-11357HIGH8.8A security flaw has been discovered in code-projects Simple Banking System 1.0. This issue affects some unknown processi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now