2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-63390MEDIUM5.3An authentication bypass vulnerability exists in AnythingLLM v1.8.5 in via the /api/workspaces endpoint. The endpoint fa...
CVE-2025-63389CRITICAL9.8A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and includ...
CVE-2025-63388CRITICAL9.1A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-f...
CVE-2025-63386CRITICAL9.1A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup en...
CVE-2025-14878CRITICAL9.8A security flaw has been discovered in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/wirele...
CVE-2025-14877CRITICAL9.8A vulnerability was identified in Campcodes Supplier Management System 1.0. This affects an unknown function of the file...
CVE-2025-14823MEDIUM5.3In deployments using the ScreenConnect™ Certificate Signing Extension, encrypted configuration values including an Azure...
CVE-2025-9787MEDIUM6.1Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulne...
CVE-2025-7358CRITICAL9.8Use of Hard-coded Credentials vulnerability in Utarit Informatics Services Inc. SoliClub allows Authentication Abuse. T...
CVE-2025-7047MEDIUM5.4Missing Authorization vulnerability in Utarit Informatics Services Inc. SoliClub allows Privilege Abuse. This issue aff...
CVE-2025-68325——In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_cake: Fix incorrect qlen reduction i...
CVE-2025-68324——In the Linux kernel, the following vulnerability has been resolved: scsi: imm: Fix use-after-free bug caused by unfinis...
CVE-2025-68323——In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: fix use-after-free caused by uec-...
CVE-2025-65011HIGH7.1In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) an unauthorised user can view configuration files by d...
CVE-2025-65010HIGH7.1WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) is vulnerable to Broken Access Control in initial configu...
CVE-2025-65009HIGH7.1In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) admin password is stored in configuration file as plai...
CVE-2025-65008CRITICAL9.4In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) due to lack of validation in the langGet parameter in ...
CVE-2025-65007HIGH8.7In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) due to lack of authentication in the configuration cha...
CVE-2025-64469HIGH7.8There is a stack-based buffer overflow vulnerability in NI LabVIEW in LVResFile::FindRsrcListEntry() when parsing a corr...
CVE-2025-64468HIGH8.5There is a use-after-free vulnerability in sentry!sentry_span_set_data() when parsing a corrupted VI file. This vulnera...
CVE-2025-64467HIGH7.8There is an out of bounds read vulnerability in NI LabVIEW in LVResFile::FindRsrcListEntry() when parsing a corrupted VI...
CVE-2025-64466HIGH8.5There is an out of bounds read vulnerability in NI LabVIEW in lvre!ExecPostedProcRecPost() when parsing a corrupted VI f...
CVE-2025-64465HIGH8.5There is an out of bounds read vulnerability in NI LabVIEW in lvre!DataSizeTDR() when parsing a corrupted VI file. This...
CVE-2025-64464HIGH8.5There is an out of bounds read vulnerability in NI LabVIEW in lvre!VisaWriteFromFile() when parsing a corrupted VI file....
CVE-2025-64463HIGH8.5There is an out of bounds read vulnerability in NI LabVIEW in LVResource::DetachResource() when parsing a corrupted VI f...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now