2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-59008HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PressTigers ZIP Co...
CVE-2025-58993HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS ...
CVE-2025-58991HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Cristiano Zanca WooCommerce Booking Bundle Hours allows Stored XSS. T...
CVE-2025-58215HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-57087HIGH7.5Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the countryCode parameter in the werlessAdva...
CVE-2025-57072HIGH7.5Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the staticRouteGateway parameter in the formSe...
CVE-2025-57071HIGH7.5Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the vpnUsers parameter in the formAddVpnUsers ...
CVE-2025-57070HIGH7.5Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the gstUp parameter in the guestWifiRuleRefres...
CVE-2025-57069HIGH7.5Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the pPppUser parameter in the getsinglepppuser...
CVE-2025-57064HIGH7.5Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the bindDhcpIndex parameter in the modifyDhcpR...
CVE-2025-57063HIGH7.5Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the portMappingIndex parameter in the formDelP...
CVE-2025-57062HIGH7.5Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the delDhcpIndex parameter in the formDelDhcpR...
CVE-2025-57061HIGH7.5Tenda G3 v3.0br_V15.11.0.17 was discovered to contain multiple stack overflows in the formIPMacBindModify function via t...
CVE-2025-57059HIGH7.5Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the dhcpIndex parameter in the addDhcpRule fun...
CVE-2025-57058HIGH7.5Tenda G3 v3.0br_V15.11.0.17 was discovered to contain multiple stack overflows in the formSetDebugCfg function via the p...
CVE-2025-57057HIGH7.5Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the listStr parameter in the ipMacBindListStor...
CVE-2025-55317HIGH7.8Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attack...
CVE-2025-55316HIGH7.8External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally.
CVE-2025-55245HIGH7.8Improper link resolution before file access ('link following') in Xbox allows an authorized attacker to elevate privileg...
CVE-2025-55243HIGH7.5Exposure of sensitive information to an unauthorized actor in Microsoft Office Plus allows an unauthorized attacker to p...
CVE-2025-55236HIGH7.8Time-of-check time-of-use (toctou) race condition in Graphics Kernel allows an authorized attacker to execute code local...
CVE-2025-55228HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX all...
CVE-2025-55227HIGH8.8Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized a...
CVE-2025-55224HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX all...
CVE-2025-55223HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now