2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-11234HIGH7.5A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSourc...
CVE-2025-11223HIGH8.4Installer of Panasonic AutoDownloader version 1.2.8 contains an issue with the DLL search path, which may lead ...
CVE-2025-0616HIGH8.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknolojik Center ...
CVE-2025-59536HIGH8.8Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the sta...
CVE-2025-59300HIGH7.8Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an atta...
CVE-2025-59299HIGH7.8Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an atta...
CVE-2025-59298HIGH7.8Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an atta...
CVE-2025-59297HIGH7.8Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an atta...
CVE-2025-61668HIGH8.7Volto is a ReactJS-based frontend for the Plone Content Management System. Versions 16.34.0 and below, 17.0.0 through 17...
CVE-2025-61666HIGH8.7Traccar is an open source GPS tracking system. Default installs of Traccar on Windows between versions 6.1- 6.8.1 and n...
CVE-2025-61600HIGH7.5Stalwart is a mail and collaboration server. Versions 0.13.3 and below contain an unbounded memory allocation vulnerabil...
CVE-2025-61665HIGH7.5WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Broken ...
CVE-2025-61604HIGH7.1WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Cross-S...
CVE-2025-61595HIGH8.8MANTRA is a purpose-built RWA Layer 1 Blockchain, capable of adherence to real world regulatory requirements. Versions 4...
CVE-2025-10653HIGH8.6An unauthenticated debug port may allow access to the device file system.
CVE-2025-59835HIGH8.6LangBot is a global IM bot platform designed for LLMs. In versions 4.1.0 up to but not including 4.3.5, authorized attac...
CVE-2025-54315HIGH7.1The Matrix specification before 1.16 (i.e., with a room version before 12) lacks create event uniqueness.
CVE-2025-49090HIGH7.1The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient...
CVE-2025-32942HIGH7.2SSH Tectia Server before 6.6.6 sometimes allows attackers to read and alter a user's session traffic.
CVE-2025-60663HIGH7.5Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanMTU parameter in the fromAdvSetMacMtuWan f...
CVE-2025-59409HIGH7.5Flock Safety Falcon and Sparrow License Plate Readers OPM1.171019.026 ship with development Wi-Fi credentials (test_flck...
CVE-2025-59405HIGH7.5The Flock Safety Peripheral com.flocksafety.android.peripheral application 7.38.3 for Android (installed on Falcon and S...
CVE-2025-34208HIGH7.5Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) store user passwords u...
CVE-2025-60662HIGH7.5Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanSpeed parameter in the fromAdvSetMacMtuWan...
CVE-2025-60660HIGH7.5Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the mac parameter in the fromAdvSetMacMtuWan func...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now