2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-13723HIGH7.5IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to o...
CVE-2025-13718HIGH7.5IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacke...
CVE-2025-12455HIGH7.5Observable response discrepancy vulnerability in OpenText™ Vertica allows Password Brute Forcing.   The vulnerability co...
CVE-2025-70873HIGH7.5An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier al...
CVE-2025-68623HIGH8.8In Microsoft DirectX End-User Runtime Web Installer 9.29.1974.0, a low-privilege user can replace an executable file dur...
CVE-2025-67037HIGH8.8An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "tunne...
CVE-2025-67036HIGH8.8An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log files by specifying th...
CVE-2025-67034HIGH8.8An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "name"...
CVE-2025-14513HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and ...
CVE-2025-13929HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.0 before 18.7.6, 18.8 before 18.8.6, and 1...
CVE-2025-12690HIGH7.8Execution with unnecessary privileges in Forcepoint NGFW Engine allows local privilege escalation.This issue affects NGF...
CVE-2025-70027HIGH7.5An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. This ...
CVE-2025-67298HIGH8.1An issue in ClasroomIO before v.0.2.6 allows a remote attacker to escalate privileges via the endpoints /api/verify and ...
CVE-2025-13067HIGH8.8The Royal Addons for Elementor plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and in...
CVE-2025-20105HIGH8.7Improper input validation in some UEFI firmware SMM module for the Intel(R) reference platforms may allow an escalation ...
CVE-2025-20068HIGH7.1Improper input validation in the UEFI ImcErrorHandler module for some Intel(R) reference platforms may allow an escalati...
CVE-2025-20064HIGH8.7Improper input validation in the UEFI FlashUcAcmSmm module for some Intel(R) reference platforms may allow an escalation...
CVE-2025-20028HIGH7.1Time-of-check time-of-use race condition in the WheaERST SMM module for some Intel(R) reference platforms may allow an e...
CVE-2025-20027HIGH7.1Improper input validation in the UEFI WheaERST module for some Intel(R) reference platforms may allow an escalation of p...
CVE-2025-70802HIGH8.4Tenda G1V3.1si V16.01.7.8 Firmware V16.01.7.8 was discovered to contain a hardcoded password vulnerability in /etc_ro/sh...
CVE-2025-70798HIGH8.4Tenda i24V3.0si V3.0.0.5 Firmware V3.0.0.5 was discovered to contain a hardcoded password vulnerability in /etc_ro/shado...
CVE-2025-70244HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formWlanSetup.
CVE-2025-36920HIGH8.4In hyp_alloc of arch/arm64/kvm/hyp/nvhe/alloc.c, there is a possible out of bounds write due to improper input validatio...
CVE-2025-70251HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formWlanGuestSetup.
CVE-2025-70249HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizard2.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now