2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-70247HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizard1.
CVE-2025-70246HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formVirtualServ.
CVE-2025-70242HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formSetWanPPTP.
CVE-2025-70227HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the nextPage parameter to goform/formLanguageChange.
CVE-2025-48611HIGH7.8In DeviceId of DeviceId.java, there is a possible desync in persistence due to a missing bounds check. This could lead t...
CVE-2025-13219HIGH7.5IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive information in URL parameters. This may lead to information...
CVE-2025-68648HIGH7.2A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer ...
CVE-2025-66178HIGH7.2A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F...
CVE-2025-56421HIGH7.5SQL Injection vulnerability in LimeSurvey before v.6.15.4+250710 allows a remote attacker to obtain sensitive informatio...
CVE-2025-54820HIGH8.1A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiM...
CVE-2025-54659HIGH7.5An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] vulnerability i...
CVE-2025-49784HIGH7.2An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiA...
CVE-2025-48418HIGH7.2A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, F...
CVE-2025-13957HIGH7.5CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause information disclosure and remote code exec...
CVE-2025-11739HIGH7.8CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administr...
CVE-2025-70028HIGH7.5An issue pertaining to CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') was discov...
CVE-2025-70031HIGH8.8An issue pertaining to CWE-352: Cross-Site Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.
CVE-2025-70030HIGH7.5An issue pertaining to CWE-1333: Inefficient Regular Expression Complexity (4.19) was discovered in Sunbird-Ed SunbirdEd...
CVE-2025-68402HIGH8.2FreshRSS is a free, self-hostable RSS aggregator. From 57e1a37 - 00f2f04, the lengths of the nonce was changed from 40 c...
CVE-2025-62166HIGH7.5FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication...
CVE-2025-70038HIGH8.8An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in linagora Tw...
CVE-2025-70034HIGH7.5An issue pertaining to CWE-1333: Inefficient Regular Expression Complexity (4.19) was discovered in mscdex ssh2 v1.17.0.
CVE-2025-15568HIGH8A command injection vulnerability was identified in the web module of Archer AXE75 v1.6/v1.0 router. An authenticated a...
CVE-2025-70048HIGH7.5An issue pertaining to CWE-319: Cleartext Transmission of Sensitive Information was discovered in Nexusoft NexusInterfac...
CVE-2025-70047HIGH7.5An issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in Nexusoft NexusInterface v3.2.0-beta....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now