2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-70250 | HIGH | 7.5 | 0.5% | Mar 9, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formdumpeasysetup. |
| CVE-2025-70243 | HIGH | 7.5 | 0.6% | Mar 9, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard534. |
| CVE-2025-70238 | HIGH | 7.5 | 0.6% | Mar 9, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard52. |
| CVE-2025-70059 | HIGH | 7.5 | 0.3% | Mar 9, 2026 | An issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in YMFE yapi v1.12.0 and allows attacke... |
| CVE-2025-15576 | HIGH | 7.5 | 0.1% | Mar 9, 2026 | If two sibling jails are restricted to separate filesystem trees, which is to say that neither of the two jail root dire... |
| CVE-2025-15547 | HIGH | 8.8 | 0.1% | Mar 9, 2026 | By default, jailed processes cannot mount filesystems, including nullfs(4). However, the allow.mount.nullfs option enab... |
| CVE-2025-14769 | HIGH | 7.5 | 1.1% | Mar 9, 2026 | In some cases, the `tcp-setmss` handler may free the packet data and throw an error without halting the rule processing ... |
| CVE-2025-14558 | HIGH | 7.2 | 6.3% | Mar 9, 2026 | The rtsol(8) and rtsold(8) programs do not validate the domain search list options provided in router advertisement mess... |
| CVE-2025-69219 | HIGH | 8.8 | 0.7% | Mar 9, 2026 | A user with access to the DB could craft a database entry that would result in executing code on Triggerer - which gives... |
| CVE-2025-69279 | HIGH | 7.5 | 0.2% | Mar 9, 2026 | In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv... |
| CVE-2025-69278 | HIGH | 7.5 | 0.2% | Mar 9, 2026 | In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv... |
| CVE-2025-61616 | HIGH | 7.5 | 0.3% | Mar 9, 2026 | In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv... |
| CVE-2025-61615 | HIGH | 7.5 | 0.3% | Mar 9, 2026 | In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv... |
| CVE-2025-61614 | HIGH | 7.5 | 0.3% | Mar 9, 2026 | In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv... |
| CVE-2025-61613 | HIGH | 7.5 | 0.3% | Mar 9, 2026 | In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv... |
| CVE-2025-61612 | HIGH | 7.5 | 0.3% | Mar 9, 2026 | In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv... |
| CVE-2025-61611 | HIGH | 7.5 | 0.6% | Mar 9, 2026 | In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional ... |
| CVE-2025-41772 | HIGH | 7.5 | 0.3% | Mar 9, 2026 | An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL ... |
| CVE-2025-41767 | HIGH | 7.2 | 0.2% | Mar 9, 2026 | A high-privileged remote attacker can fully compromise the device by abusing an update signature bypass vulnerability in... |
| CVE-2025-41766 | HIGH | 8.8 | 0.5% | Mar 9, 2026 | A low-privileged remote attacker can trigger a stack-based buffer overflow via a crafted HTTP POST request using the ubr... |
| CVE-2025-41761 | HIGH | 7.8 | 0.2% | Mar 9, 2026 | A low‑privileged local attacker who gains access to the UBR service account (e.g., via SSH) can escalate privileges to o... |
| CVE-2025-41758 | HIGH | 8.8 | 0.5% | Mar 9, 2026 | A low-privileged remote attacker can exploit an arbitrary file write vulnerability in the wwupload.cgi endpoint. Due to ... |
| CVE-2025-41757 | HIGH | 8.8 | 0.5% | Mar 9, 2026 | A low-privileged remote attacker can abuse the backup restore functionality of UBR (ubr-restore) which runs with elevate... |
| CVE-2025-41756 | HIGH | 8.1 | 0.3% | Mar 9, 2026 | A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpo... |
| CVE-2025-14675 | HIGH | 7.2 | 0.7% | Mar 7, 2026 | The Meta Box plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now