2025 CVE Vulnerabilities

45,159 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-9356HIGH8.8A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.0...
CVE-2025-9355HIGH8.8A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002...
CVE-2025-52451HIGH8.5Improper Input Validation vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - create-data-source-...
CVE-2025-26498HIGH7.3Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (establish-...
CVE-2025-26497HIGH7.3Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Edito...
CVE-2025-6791HIGH8.8In the monitoring event logs page, it is possible to alter the http request to insert a reflect payload in the DB. Cause...
CVE-2025-55454HIGH8.8An authenticated arbitrary file upload vulnerability in the component /msg/sendfiles of DooTask v1.0.51 allows attackers...
CVE-2025-54813HIGH7.5Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using JSONLayout, not all payload bytes a...
CVE-2025-4650HIGH7.2User with high privileges is able to introduce a SQLi using the Meta Service indicator page. Caused by an Improper Neutr...
CVE-2025-55581HIGH7.3D-Link DCS-825L firmware version 1.08.01 and possibly prior versions contain an insecure implementation in the mydlink-w...
CVE-2025-52287HIGH8.8OperaMasks SDK ELite Script Engine v0.5.0 was discovered to contain a deserialization vulnerability.
CVE-2025-52085HIGH8.8An SQL injection vulnerability in Yoosee application v6.32.4 allows authenticated users to inject arbitrary SQL queries ...
CVE-2025-57800HIGH8.8Audiobookshelf is an open-source self-hosted audiobook server. In versions 2.6.0 through 2.26.3, the application does no...
CVE-2025-57771HIGH8.1Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions prior to 3.25.5, Roo-Code fa...
CVE-2025-55745HIGH8.8UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Versions 0.3.0 and ...
CVE-2025-55634HIGH7.5Incorrect access control in the RTMP server settings of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firm...
CVE-2025-55630HIGH7.3A discrepancy in the error message returned by the login function of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with...
CVE-2025-55741HIGH8.1UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. In versions 0.3.0 a...
CVE-2025-55611HIGH7.5D-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formLanguageChange function via the nextPage parameter.
CVE-2025-55606HIGH7.5Tenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the fromAdvSetMacMtuWan function via the serverName parame...
CVE-2025-55605HIGH7.5Tenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the saveParentControlInfo function via the deviceName para...
CVE-2025-55603HIGH7.5Tenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the fromSetSysTime function via the ntpServer parameter.
CVE-2025-55602HIGH7.5D-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formSysCmd function via the submit-url parameter.
CVE-2025-55599HIGH7.5D-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formWlanSetup function via the parameter f_wds_wepKey.
CVE-2025-52094HIGH7.8Insecure Permissions vulnerability in PDQ Smart Deploy V.3.0.2040 allows a local attacker to execute arbtirary code via ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now