2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-62858MEDIUM6.5A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker...
CVE-2025-71315MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/vkms: Convert to DRM's vblank timer Replace vk...
CVE-2025-12656LOW3.8The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory de...
CVE-2025-71318CRITICAL9.8NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated ...
CVE-2025-71317CRITICAL9.8NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that grants administrative acce...
CVE-2025-5090HIGH7.1CVX is not resilient to unexpected messages from a connected switch. This leads to agent crashes on CVX causing instabil...
CVE-2025-5089HIGH7.1In a CVX cluster, an EOS switch connected to a CVX server is not resilient to certain malformed messages received from t...
CVE-2025-5088HIGH8.7An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. Note that thi...
CVE-2025-59174HIGH7.1Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large v...
CVE-2025-8873HIGH8.7On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane to st...
CVE-2025-71316CRITICAL9.8SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANS...
CVE-2025-65640MEDIUM6.3Cross Site Scripting (XSS) vulnerability in the "Task in Progress / Recent" page in Arket Globe Document Intelligence 5....
CVE-2025-69755HIGH8.2An issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a remote attacker to obtain sensitive information and ...
CVE-2025-67448HIGH7.1The SMS module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to stored XSS. The application does not...
CVE-2025-67447CRITICAL9.8The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to OS command inje...
CVE-2025-67446CRITICAL9.8Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router u...
CVE-2025-62338LOW3.3HCL BigFix Cloud Lifecycle Management is affected by lack of input validation.  This low-level flaw allows unauthorized ...
CVE-2025-59874HIGH8.1HCL Hive Telco Observability is affected by  a Required directives missing from the CSP issue is detected in keycloak co...
CVE-2025-46638HIGH7.5Dell BSAFE SSL-J contains an allocation of resources without limits or throttling vulnerability. An unauthenticated remo...
CVE-2025-52612HIGH8.8HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site script...
CVE-2025-52611MEDIUM4.3HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to ...
CVE-2025-52609MEDIUM5.3HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by...
CVE-2025-52608MEDIUM4.3HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing s...
CVE-2025-52606MEDIUM4.3HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an ar...
CVE-2025-12694HIGH7.8A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now