2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-70250HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formdumpeasysetup.
CVE-2025-70243HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard534.
CVE-2025-70238HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard52.
CVE-2025-70059HIGH7.5An issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in YMFE yapi v1.12.0 and allows attacke...
CVE-2025-15576HIGH7.5If two sibling jails are restricted to separate filesystem trees, which is to say that neither of the two jail root dire...
CVE-2025-15547HIGH8.8By default, jailed processes cannot mount filesystems, including nullfs(4). However, the allow.mount.nullfs option enab...
CVE-2025-14769HIGH7.5In some cases, the `tcp-setmss` handler may free the packet data and throw an error without halting the rule processing ...
CVE-2025-14558HIGH7.2The rtsol(8) and rtsold(8) programs do not validate the domain search list options provided in router advertisement mess...
CVE-2025-69219HIGH8.8A user with access to the DB could craft a database entry that would result in executing code on Triggerer - which gives...
CVE-2025-69279HIGH7.5In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv...
CVE-2025-69278HIGH7.5In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv...
CVE-2025-61616HIGH7.5In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv...
CVE-2025-61615HIGH7.5In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv...
CVE-2025-61614HIGH7.5In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv...
CVE-2025-61613HIGH7.5In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv...
CVE-2025-61612HIGH7.5In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv...
CVE-2025-61611HIGH7.5In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional ...
CVE-2025-41772HIGH7.5An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL ...
CVE-2025-41767HIGH7.2A high-privileged remote attacker can fully compromise the device by abusing an update signature bypass vulnerability in...
CVE-2025-41766HIGH8.8A low-privileged remote attacker can trigger a stack-based buffer overflow via a crafted HTTP POST request using the ubr...
CVE-2025-41761HIGH7.8A low‑privileged local attacker who gains access to the UBR service account (e.g., via SSH) can escalate privileges to o...
CVE-2025-41758HIGH8.8A low-privileged remote attacker can exploit an arbitrary file write vulnerability in the wwupload.cgi endpoint. Due to ...
CVE-2025-41757HIGH8.8A low-privileged remote attacker can abuse the backup restore functionality of UBR (ubr-restore) which runs with elevate...
CVE-2025-41756HIGH8.1A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpo...
CVE-2025-14675HIGH7.2The Meta Box plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now