2025 CVE Vulnerabilities

45,158 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-6203HIGH7.5A malicious user may submit a specially-crafted complex payload that otherwise meets the default request size limit whic...
CVE-2025-9580HIGH8.8A security vulnerability has been detected in LB-LINK BL-X26 1.2.8. This affects an unknown function of the file /goform...
CVE-2025-9579HIGH8.8A weakness has been identified in LB-LINK BL-X26 1.2.8. The impacted element is an unknown function of the file /goform/...
CVE-2025-9577HIGH7A security flaw has been discovered in TOTOLINK X2000R up to 2.0.0. The affected element is an unknown function of the f...
CVE-2025-57215HIGH7.5Tenda AC10 v4.0 firmware v16.03.10.20 was discovered to contain a stack overflow via the function get_parentControl_list...
CVE-2025-9576HIGH7A vulnerability was identified in seeedstudio ReSpeaker LinkIt7688. Impacted is an unknown function of the file /etc/sha...
CVE-2025-9575HIGH8.8A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.0...
CVE-2025-58049HIGH7.5XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions fro...
CVE-2025-58047HIGH7.5Volto is a React based frontend for the Plone Content Management System. In versions from 19.0.0-alpha.1 to before 19.0....
CVE-2025-58335HIGH7.5In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54...
CVE-2025-58334HIGH8.8In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-p...
CVE-2025-57767HIGH7.5Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.15.2, 21.10.2, and 22.5.2...
CVE-2025-8067HIGH8.5A flaw was found in the Udisks daemon, where it allows unprivileged users to create loop devices using the D-BUS system....
CVE-2025-9578HIGH7.8Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protec...
CVE-2025-54742HIGH8.8Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This...
CVE-2025-54731HIGH8.1Improper Control of Generation of Code ('Code Injection') vulnerability in emarket-design YouTube Showcase youtube-showc...
CVE-2025-54724HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Golo golo al...
CVE-2025-54716HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-54714HIGH7.1Missing Authorization vulnerability in Dylan James Zephyr Project Manager zephyr-project-manager allows Exploiting Incor...
CVE-2025-54710HIGH7.1Missing Authorization vulnerability in bPlugins Tiktok Feed b-tiktok-feed allows Accessing Functionality Not Properly Co...
CVE-2025-54029HIGH7.7Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in extendons WooCommerce cs...
CVE-2025-53588HIGH7.7Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Dmitry V. (CEO of "UKR S...
CVE-2025-53584HIGH8.1Deserialization of Untrusted Data vulnerability in emarket-design WP Ticket Customer Service Software & Support Ticket S...
CVE-2025-53583HIGH8.1Deserialization of Untrusted Data vulnerability in emarket-design Employee Spotlight employee-spotlight allows Object In...
CVE-2025-53579HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in captcha.eu Captcha...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now