2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-34165HIGH8.8A stack-based buffer overflow vulnerability in NetSupport Manager 14.x versions prior to 14.12.0000 allows a remote, una...
CVE-2025-58159HIGH8.8WeGIA is a Web manager for charitable institutions. Prior to version 3.4.11, a remote code execution vulnerability was i...
CVE-2025-58157HIGH7.5gnark is a zero-knowledge proof system framework. In version 0.12.0, there is a potential denial of service vulnerabilit...
CVE-2025-57822HIGH8.2Next.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next()...
CVE-2025-56577HIGH8.4An issue in Evope Core v.1.1.3.20 allows a local attacker to obtain sensitive information via the use of hard coded cryp...
CVE-2025-9667HIGH8.8A vulnerability was detected in code-projects Simple Grading System 1.0. This affects an unknown part of the file /delet...
CVE-2025-9666HIGH8.8A security vulnerability has been detected in code-projects Simple Grading System 1.0. Affected by this issue is some un...
CVE-2025-9665HIGH8.8A weakness has been identified in code-projects Simple Grading System 1.0. Affected by this vulnerability is an unknown ...
CVE-2025-9377HIGH7.2The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7...
CVE-2025-58158HIGH8.8Harness Open Source is an end-to-end developer platform with Source Control Management, CI/CD Pipelines, Hosted Develope...
CVE-2025-52861HIGH7A path traversal vulnerability has been reported to affect VioStor. If a remote attacker gains an administrator account,...
CVE-2025-44015HIGH8.4A command injection vulnerability has been reported to affect HybridDesk Station. If an attacker gains local network acc...
CVE-2025-30278HIGH8.8An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a...
CVE-2025-30277HIGH8.8An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a...
CVE-2025-30273HIGH8.1An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If a remote att...
CVE-2025-30264HIGH8.8A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack...
CVE-2025-29894HIGH8.8An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the...
CVE-2025-29893HIGH8.8An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the...
CVE-2025-29887HIGH7.2A command injection vulnerability has been reported to affect QuRouter 2.5.1. If a remote attacker gains an administrato...
CVE-2025-9664HIGH8.8A security flaw has been discovered in code-projects Simple Grading System 1.0. Affected is an unknown function of the f...
CVE-2025-9663HIGH8.8A vulnerability was identified in code-projects Simple Grading System 1.0. This impacts an unknown function of the file ...
CVE-2025-55763HIGH7.5Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code...
CVE-2025-5808HIGH7.3Improper Input Validation vulnerability in OpenText Self Service Password Reset allows Authentication Bypass.This issue ...
CVE-2025-47909HIGH7.3Hosts listed in TrustedOrigins implicitly allow requests from the corresponding HTTP origins, allowing network MitMs to ...
CVE-2025-53508HIGH8.6Multiple products provided by iND Co.,Ltd contain an OS command injection vulnerability. If exploited, an arbitrary OS c...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now