2025 CVE Vulnerabilities

45,330 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-58761HIGH7.5Tautulli is a Python based monitoring and tracking tool for Plex Media Server. The `real_pms_image_proxy` endpoint in Ta...
CVE-2025-58760HIGH7.5Tautulli is a Python based monitoring and tracking tool for Plex Media Server. The `/image` API endpoint in Tautulli v2....
CVE-2025-58758HIGH7.3TinyEnv is an environment variable loader for PHP applications. In versions 1.0.1, 1.0.2, 1.0.9, and 1.0.10, TinyEnv did...
CVE-2025-58753HIGH7.5Copyparty is a portable file server. In versions prior to 1.19.8, there was a missing permission-check in the shares fea...
CVE-2025-58180HIGH8.8OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11....
CVE-2025-58063HIGH7.1CoreDNS is a DNS server that chains plugins. Starting in version 1.2.0 and prior to version 1.12.4, the CoreDNS etcd plu...
CVE-2025-54257HIGH7.8Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Use After Free vulnerabil...
CVE-2025-53914HIGH7Excessive Privileges vulnerability in Calix GigaCenter ONT (Broadcom SoC modules) allows Privilege Abuse.This issue affe...
CVE-2025-53913HIGH7Excessive Privileges vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows Privilege Abuse.This issue aff...
CVE-2025-57278HIGH8.8The LB-Link BL-CPE300M AX300 4G LTE Router firmware version BL-R8800_B10_ALK_SL_V01.01.02P42U14_06 does not implement pr...
CVE-2025-57060HIGH7.5Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the rules parameter in the dns_forward_rule_st...
CVE-2025-55047HIGH8.4CWE-798 Use of Hard-coded Credentials
CVE-2025-54256HIGH8.6Dreamweaver Desktop versions 21.5 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that cou...
CVE-2025-54242HIGH7.8Premiere Pro versions 25.3, 24.6.5 and earlier are affected by a Use After Free vulnerability that could result in arbit...
CVE-2025-29089HIGH7.5An issue in TP-Link AX10 Ax1500 v.1.3.10 Build (20230130) allows a remote attacker to obtain sensitive information
CVE-2025-10164HIGH7.3A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the fi...
CVE-2025-57086HIGH7.5Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the String parameter in the formDeleteMeshNo...
CVE-2025-57078HIGH7.5Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the pppoeServerWhiteMacIndex parameter in the ...
CVE-2025-10199HIGH7.8A local privilege escalation vulnerability exists in Sunshine for Windows (version v2025.122.141614 and likely prior ver...
CVE-2025-10198HIGH7.8Sunshine for Windows, version v2025.122.141614, contains a DLL search-order hijacking vulnerability, allowing attackers ...
CVE-2025-5005HIGH7.3A vulnerability was detected in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.5.4. This affects an unk...
CVE-2025-59008HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PressTigers ZIP Co...
CVE-2025-58993HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS ...
CVE-2025-58991HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Cristiano Zanca WooCommerce Booking Bundle Hours allows Stored XSS. T...
CVE-2025-58215HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now