2025 CVE Vulnerabilities

45,334 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-4650HIGH7.2User with high privileges is able to introduce a SQLi using the Meta Service indicator page. Caused by an Improper Neutr...
CVE-2025-55581HIGH7.3D-Link DCS-825L firmware version 1.08.01 and possibly prior versions contain an insecure implementation in the mydlink-w...
CVE-2025-52287HIGH8.8OperaMasks SDK ELite Script Engine v0.5.0 was discovered to contain a deserialization vulnerability.
CVE-2025-52085HIGH8.8An SQL injection vulnerability in Yoosee application v6.32.4 allows authenticated users to inject arbitrary SQL queries ...
CVE-2025-57800HIGH8.8Audiobookshelf is an open-source self-hosted audiobook server. In versions 2.6.0 through 2.26.3, the application does no...
CVE-2025-57771HIGH8.1Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions prior to 3.25.5, Roo-Code fa...
CVE-2025-55745HIGH8.8UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Versions 0.3.0 and ...
CVE-2025-55634HIGH7.5Incorrect access control in the RTMP server settings of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firm...
CVE-2025-55630HIGH7.3A discrepancy in the error message returned by the login function of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with...
CVE-2025-55741HIGH8.1UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. In versions 0.3.0 a...
CVE-2025-55611HIGH7.5D-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formLanguageChange function via the nextPage parameter.
CVE-2025-55606HIGH7.5Tenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the fromAdvSetMacMtuWan function via the serverName parame...
CVE-2025-55605HIGH7.5Tenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the saveParentControlInfo function via the deviceName para...
CVE-2025-55603HIGH7.5Tenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the fromSetSysTime function via the ntpServer parameter.
CVE-2025-55602HIGH7.5D-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formSysCmd function via the submit-url parameter.
CVE-2025-55599HIGH7.5D-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formWlanSetup function via the parameter f_wds_wepKey.
CVE-2025-52094HIGH7.8Insecure Permissions vulnerability in PDQ Smart Deploy V.3.0.2040 allows a local attacker to execute arbtirary code via ...
CVE-2025-51605HIGH8.1An issue was discovered in Shopizer 3.2.7. The server's CORS implementation reflects the client-supplied Origin header v...
CVE-2025-50674HIGH7.8An issue was discovered in the changePassword method in file /usr/share/php/openmediavault/system/user.inc in OpenMediaV...
CVE-2025-38670HIGH7.1In the Linux kernel, the following vulnerability has been resolved: arm64/entry: Mask DAIF in cpu_switch_to(), call_on_...
CVE-2025-38667HIGH7.8In the Linux kernel, the following vulnerability has been resolved: iio: fix potential out-of-bound write The buffer i...
CVE-2025-38666HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: appletalk: Fix use-after-free in AARP proxy pr...
CVE-2025-38662HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8365-dai-i2s: pass correct size t...
CVE-2025-38657HIGH7.1In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: mcc: prevent shift wrapping in rtw89_c...
CVE-2025-38656HIGH7.8In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: Fix error code in iwl_op_mode_dvm_st...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now