2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-55038HIGH7.6An authorization bypass vulnerability has been discovered in the Click Plus C2-03CPU2 device firmware version 3.60. Thro...
CVE-2025-59484HIGH8.7The use of a broken or risky cryptographic algorithm was discovered in firmware version 3.60 of the Click Plus PLC. The ...
CVE-2025-59826HIGH7.6Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, non-admin users can create arbitrary challenges, pote...
CVE-2025-59822HIGH7.5Http4s is a Scala interface for HTTP services. In versions from 1.0.0-M1 to before 1.0.0-M45 and before 0.23.31, http4s ...
CVE-2025-59534HIGH7.8CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL...
CVE-2025-57638HIGH7.5Buffer overflow vulnerability in Tenda AC9 1.0 via the user supplied sys.vendor configuration value.
CVE-2025-57637HIGH7.5Buffer overflow vulnerability in D-Link DI-7100G 2020-02-21 in the sub_451754 function of the jhttpd service in the viav...
CVE-2025-54081HIGH7Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineS...
CVE-2025-51005HIGH7.5A heap-buffer-overflow vulnerability exists in the tcpliveplay utility of the tcpreplay-4.5.1. When a crafted pcap file ...
CVE-2025-8410HIGH7.4Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation. This issue affects...
CVE-2025-56394HIGH7.5Free5gc 4.0.1 is vulnerable to Buffer Overflow. The AMF incorrectly validates the 5GS mobile identity, resulting in slic...
CVE-2025-55780HIGH7.5A null pointer dereference occurs in the function break_word_for_overflow_wrap() in MuPDF 1.26.4 when rendering a malfor...
CVE-2025-52905HIGH7.5Improper Input Validation vulnerability in TOTOLINK X6000R allows Flooding.This issue affects X6000R: through V9.4.0cu.1...
CVE-2025-4582HIGH7.1Buffer Over-read, Off-by-one Error vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation, ...
CVE-2025-9900HIGH8.8A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes ...
CVE-2025-5717HIGH7.2An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input valida...
CVE-2025-9844HIGH8.8Uncontrolled Search Path Element vulnerability in Salesforce Salesforce CLI on Windows allows Replace Trusted Executable...
CVE-2025-8354HIGH7.8A maliciously crafted RFA file, when parsed through Autodesk Revit, can force a Type Confusion vulnerability. A maliciou...
CVE-2025-6921HIGH7.5The huggingface/transformers library, versions prior to 4.53.0, is vulnerable to Regular Expression Denial of Service (R...
CVE-2025-10184HIGH8.2The vulnerability allows any application installed on the device to read SMS/MMS data and metadata from the system-provi...
CVE-2025-9966HIGH7.3Improper privilege management vulnerability in Novakon P series allows attackers to gain root privileges if one service ...
CVE-2025-9964HIGH8.6No password for the root user is set in Novakon P series. This allows phyiscal attackers to enter the console easily. T...
CVE-2025-10244HIGH8.7A maliciously crafted HTML payload, when rendered by the Autodesk Fusion desktop application, can trigger a Stored Cross...
CVE-2025-9798HIGH8.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netcad Soft...
CVE-2025-10848HIGH8.8A vulnerability was identified in Campcodes Society Membership Information System 1.0. This issue affects some unknown p...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now