2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-60947HIGH8.8Census CSWeb 8.0.1 allows arbitrary file upload. A remote, authenticated attacker could upload a malicious file, possibl...
CVE-2025-60946HIGH8.8Census CSWeb 8.0.1 allows arbitrary file path input. A remote, authenticated attacker could access unintended file direc...
CVE-2025-15606HIGH7.5A Denial-of-Service (DoS) vulnerability in the httpd component of TP-Link's TD-W8961N v4.0 due to improper input sanitiz...
CVE-2025-15605HIGH7.3A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 enables...
CVE-2025-15519HIGH7.2Improper input handling in a modem-management administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600...
CVE-2025-15518HIGH7.2Improper input handling in a wireless-control administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600...
CVE-2025-15517HIGH8.1A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoin...
CVE-2025-10679HIGH7.3The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for...
CVE-2025-14037HIGH8.1The Invelity Product Feeds plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versi...
CVE-2025-63261HIGH7.8AWStats 8.0 is vulnerable to Command Injection via the open function
CVE-2025-55988HIGH7.2An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a dire...
CVE-2025-67260HIGH8.8The Terrapack software, from ASTER TEC / ASTER S.p.A., with the indicated components and versions has a file upload vuln...
CVE-2025-46597HIGH7.5Bitcoin Core 0.13.0 through 29.x has an integer overflow.
CVE-2025-69720HIGH7.8The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in prog...
CVE-2025-71260HIGH8.8BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in ...
CVE-2025-71259HIGH7.1BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in ...
CVE-2025-71258HIGH7.1BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in ...
CVE-2025-68836HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Markbeljaars Table...
CVE-2025-67618HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ArtstudioWorks Bro...
CVE-2025-53222HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Opt-...
CVE-2025-50001HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Comp...
CVE-2025-58112HIGH8.8Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034) allows the generation of customized reports v...
CVE-2025-55046HIGH8.1MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted content s...
CVE-2025-55045HIGH7.1The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address information...
CVE-2025-55044HIGH8.8The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from the tra...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now