2025 CVE Vulnerabilities

45,168 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14850CRITICAL9.1Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files.
CVE-2025-14849CRITICAL9.8Advantech WebAccess/SCADA  is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute ar...
CVE-2025-14848MEDIUM5.3Advantech WebAccess/SCADA is vulnerable to absolute directory traversal, which may allow an attacker to determine the ex...
CVE-2025-13911HIGH7.3The vulnerability affects Ignition SCADA applications where Python scripting is utilized for automation purposes. The v...
CVE-2025-67163MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to execute arbitrary ...
CVE-2025-65566HIGH7.5A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1....
CVE-2025-64400MEDIUM4.1Control Panel provides an API for pre-registering into an enrollment and organization prior to a user's first login. Th...
CVE-2025-14889MEDIUM6.3A security flaw has been discovered in Campcodes Advanced Voting Management System 1.0. The impacted element is an unkno...
CVE-2025-67745HIGH7.5MyHoard is a daemon for creating, managing and restoring MySQL backups. Starting in version 1.0.1 and prior to version 1...
CVE-2025-65568HIGH7.5A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1....
CVE-2025-65567HIGH7.5A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1....
CVE-2025-65565HIGH7.5A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1....
CVE-2025-65564HIGH7.5A denial-of-service vulnerability exists in the omec-upf (upf-epc-pfcpiface) in version upf-epc-pfcpiface:2.1.3-dev. Whe...
CVE-2025-65563HIGH7.5A denial-of-service vulnerability exists in the omec-project UPF (component upf-epc/pfcpiface) up to at least version up...
CVE-2025-65562HIGH7.5The free5GC UPF suffers from a lack of bounds checking on the SEID when processing PFCP Session Deletion Requests. An un...
CVE-2025-65561HIGH7.5An issue was discovered in function LocalNode.Sess in free5GC 4.1.0 allowing attackers to cause a denial of service or o...
CVE-2025-65559HIGH7.5An issue was discovered in Open5GS 2.7.5-49-g465e90f, when processing a PFCP Session Establishment Request (type=50), th...
CVE-2025-63387HIGH7.5Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to th...
CVE-2025-59949MEDIUM6.5FreshRSS is a free, self-hostable RSS aggregator. Versions prior to 1.27.1 have a logout cross-site request forgery vuln...
CVE-2025-56157CRITICAL9.8Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file inclu...
CVE-2025-14885HIGH8.8A flaw has been found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file ...
CVE-2025-14739MEDIUM6.8Access of Uninitialized Pointer vulnerability in TP-Link WR940N and WR941ND allows local unauthenticated attackers the a...
CVE-2025-14738HIGH7.5Improper authentication vulnerability in TP-Link WA850RE (httpd modules) allows unauthenticated attackers to download th...
CVE-2025-14737HIGH8Command Injection vulnerability in TP-Link WA850RE (httpd modules) allows authenticated adjacent attacker to inject arbi...
CVE-2025-66058MEDIUM6.5Missing Authorization vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectl...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now