2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-10863——Rejected reason: This CVE id was assigned but later discarded.
CVE-2025-51511CRITICAL9.8Cadmium CMS v.0.4.9 has a background arbitrary file upload vulnerability in /admin/content/filemanager/uploads.
CVE-2025-13074——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2025-65713MEDIUM4Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully val...
CVE-2025-65410MEDIUM6.2A stack overflow in the src/main.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) v...
CVE-2025-33224CRITICAL9.8NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges....
CVE-2025-33223CRITICAL9.8NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges....
CVE-2025-33222CRITICAL9.8NVIDIA Isaac Launchable contains a vulnerability where an attacker could exploit a hard-coded credential issue. A succes...
CVE-2025-29229CRITICAL9.8linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.
CVE-2025-29228CRITICAL9.8Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.
CVE-2025-67111HIGH7.5An integer overflow in the RTPS protocol implementation of OpenDDS DDS before v3.33.0 allows attackers to cause a Denial...
CVE-2025-67109CRITICAL10Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certifica...
CVE-2025-67108CRITICAL10eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure commun...
CVE-2025-65865HIGH7.5An integer overflow in eProsima Fast-DDS v3.3 allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2025-50526CRITICAL9.8Netgear EX8000 V1.0.0.126 was discovered to contain a command injection vulnerability via the switch_status function.
CVE-2025-48864——Rejected reason: This CVE id was assigned but later discarded.
CVE-2025-48863——Rejected reason: This CVE id was assigned but later discarded.
CVE-2025-45493MEDIUM6.5Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the iface parameter in the action_bandwidth function.
CVE-2025-68343——In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_receive_bulk_callback(): check ...
CVE-2025-68342——In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_receive_bulk_callback(): check ...
CVE-2025-68341CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: veth: reduce XDP no_direct return section to fix ra...
CVE-2025-68340MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: team: Move team device type change at the end of te...
CVE-2025-68339——In the Linux kernel, the following vulnerability has been resolved: atm/fore200e: Fix possible data race in fore200e_op...
CVE-2025-68338——In the Linux kernel, the following vulnerability has been resolved: net: dsa: microchip: Don't free uninitialized ksz_i...
CVE-2025-66845MEDIUM6.1A reflected Cross-Site Scripting (XSS) vulnerability has been identified in TechStore version 1.0. The user_name endpoin...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now