2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-10948HIGH8.8A vulnerability has been found in MikroTik RouterOS 7. This affects the function parse_json_element of the file /rest/ip...
CVE-2025-10467HIGH8.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PROLIZ Comp...
CVE-2025-10449HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saysis Computer Systems ...
CVE-2025-40698HIGH8.7SQL injection vulnerability in Prevengos v2.44 by Nedatec Consulting. This vulnerability allows an attacker to retrieve,...
CVE-2025-10957HIGH8.7This vulnerability exists in the Syrotech SY-GPON-2010-WADONT router due to improper access control in its FTP service. ...
CVE-2025-10942HIGH8.8A vulnerability was identified in H3C Magic B3 up to 100R002. This affects the function AddMacList/EditMacList of the fi...
CVE-2025-10941HIGH8.5A vulnerability was determined in Topaz SERVCore Teller 2.14.0-RC2/2.14.1. Affected by this issue is some unknown functi...
CVE-2025-10438HIGH8.6Path Traversal: 'dir/../../filename' vulnerability in Yordam Information Technology Consulting Education and Electrical ...
CVE-2025-54520HIGH8.6Improper Protection Against Voltage and Clock Glitches in FPGA devices, could allow an attacker with physical access to ...
CVE-2025-59833HIGH7.5Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.1.0 to before 2.3.0, the API endpoint GET /api/probl...
CVE-2025-57319HIGH7.5fast-redact is a package that provides do very fast object redaction. A Prototype Pollution vulnerability in the nestedR...
CVE-2025-57318HIGH7.5A Prototype Pollution vulnerability in the toCsv function of csvjson versions thru 5.1.0 allows attackers to inject prop...
CVE-2025-57329HIGH7.5web3-core-method is a package designed to creates the methods on the web3 modules. A Prototype Pollution vulnerability i...
CVE-2025-57328HIGH7.5toggle-array is a package designed to enables a property on the object at the specified index, while disabling the prope...
CVE-2025-57327HIGH7.5spmrc is a package that provides the rc manager for spm. A Prototype Pollution vulnerability in the set and config funct...
CVE-2025-57326HIGH7.5A Prototype Pollution vulnerability in the byGroupAndType function of sassdoc-extras v2.5.1 and before allows attackers ...
CVE-2025-57325HIGH7.5rollbar is a package designed to effortlessly track and debug errors in JavaScript applications. This package includes a...
CVE-2025-57323HIGH7.5mpregular is a package that provides a small program development framework based on RegularJS. A Prototype Pollution vul...
CVE-2025-59251HIGH7.6Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2025-57349HIGH7.5The messageformat package, an implementation of the Unicode MessageFormat 2 specification for JavaScript, is vulnerable ...
CVE-2025-57330HIGH7.5The web3-core-subscriptions is a package designed to manages web3 subscriptions. A Prototype Pollution vulnerability in ...
CVE-2025-55322HIGH7.3Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network.
CVE-2025-59343HIGH8.7tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink...
CVE-2025-59305HIGH7.6Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated use...
CVE-2025-57350HIGH8.6The csvtojson package, a tool for converting CSV data to JSON with customizable parsing capabilities, contains a prototy...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now