2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-59215HIGH7Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
CVE-2025-54860HIGH7.7Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 in order to allow manage...
CVE-2025-54818HIGH8.6Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform manage...
CVE-2025-54810HIGH8.6Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform manage...
CVE-2025-54497HIGH8.1Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management ope...
CVE-2025-53969HIGH8.8Cognex In-Sight Explorer and In-Sight Camera Firmware expose a service implementing a proprietary protocol on TCP port ...
CVE-2025-52873HIGH8.1Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management oper...
CVE-2025-57295HIGH8H3C devices running firmware version NX15V100R015 are vulnerable to unauthorized access due to insecure default credenti...
CVE-2025-57293HIGH8.8A command injection vulnerability in COMFAST CF-XR11 (firmware V2.7.2) exists in the multi_pppoe API, processed by the s...
CVE-2025-55068HIGH8.8Dover Fueling Solutions ProGauge MagLink LX4 Devices fail to handle Unix time values beyond a certain point. An attacke...
CVE-2025-54754HIGH8.6An attacker with adjacent access, without authentication, can exploit this vulnerability to retrieve a hard-coded passw...
CVE-2025-53947HIGH7.7A local attacker with low privileges on the Windows system where the software is installed can exploit this vulnerabili...
CVE-2025-47698HIGH8.6An adjacent attacker without authentication can exploit this vulnerability to retrieve a set of user-privileged credenti...
CVE-2025-59424HIGH7.3LinkAce is a self-hosted archive to collect website links. Prior to 2.3.1, a Stored Cross-Site Scripting (XSS) vulnerabi...
CVE-2025-55912HIGH7.3An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in ...
CVE-2025-50255HIGH7.8Cross Site Request Forgery (CSRF) vulnerability in Smartvista BackOffice SmartVista Suite 2.2.22 via crafted GET request...
CVE-2025-36143HIGH7.2IBM Lakehouse (watsonx.data 2.2) could allow an authenticated privileged user to execute arbitrary commands on the syste...
CVE-2025-10672HIGH7.8A vulnerability was found in whuan132 AIBattery up to 1.0.9. The affected element is an unknown function of the file AIB...
CVE-2025-40677HIGH8.7SQL injection vulnerability in Summar Software´s Portal del Empleado. This vulnerability allows an attacker to retrieve,...
CVE-2025-10207HIGH7.5Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5.
CVE-2025-8565HIGH8.1The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vul...
CVE-2025-10634HIGH8.8A weakness has been identified in D-Link DIR-823X 240126/240802/250416. The impacted element is the function sub_412E7C ...
CVE-2025-10629HIGH8.8A vulnerability was determined in D-Link DIR-852 1.00CN B09. This issue affects the function ssdpcgi_main of the file ht...
CVE-2025-10628HIGH8.8A vulnerability was found in D-Link DIR-852 1.00CN B09. This vulnerability affects unknown code of the file /htdocs/cgib...
CVE-2025-10627HIGH8.8A vulnerability has been found in SourceCodester Online Exam Form Submission 1.0. This affects an unknown part of the fi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now