2025 CVE Vulnerabilities

45,334 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-9262HIGH8.1A flaw has been found in wong2 mcp-cli 1.13.0. Affected is the function redirectToAuthorization of the file /src/oauth/p...
CVE-2025-9253HIGH8.8A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0....
CVE-2025-9252HIGH8.8A weakness has been identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.0...
CVE-2025-9251HIGH8.8A security flaw has been discovered in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/...
CVE-2025-9250HIGH8.8A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.0...
CVE-2025-9249HIGH8.8A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.0...
CVE-2025-9248HIGH8.8A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002...
CVE-2025-9247HIGH8.8A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.0...
CVE-2025-9246HIGH8.8A flaw has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1...
CVE-2025-9245HIGH8.8A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04....
CVE-2025-9244HIGH8.8A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0....
CVE-2025-9241HIGH7.5A weakness has been identified in elunez eladmin up to 2.7. This affects the function exportUser. This manipulation caus...
CVE-2025-5115HIGH7.5In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the ...
CVE-2025-54988HIGH8.4Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms al...
CVE-2025-50902HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in old-peanut Open-Shop (aka old-peanut/wechat_applet__open_source) thru...
CVE-2025-9238HIGH7.3A vulnerability was determined in Swatadru Exam-Seating-Arrangement up to 97335ccebf95468d92525f4255a2241d2b0b002f. Affe...
CVE-2025-9236HIGH8.8A vulnerability has been found in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet...
CVE-2025-55746HIGH7.5Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnera...
CVE-2025-8612HIGH7.3AOMEI Backupper Workstation Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local att...
CVE-2025-8309HIGH8.1There is an improper privilege management vulnerability identified in ManageEngine's Asset Explorer, ServiceDesk Plus, S...
CVE-2025-6183HIGH7The StrongDM macOS client incorrectly processed JSON-formatted messages. Attackers could potentially modify macOS system...
CVE-2025-6182HIGH8.5The StrongDM Windows service incorrectly handled communication related to system certificate management. Attackers could...
CVE-2025-6181HIGH8.5The StrongDM Windows service incorrectly handled input validation. Authenticated attackers could potentially exploit thi...
CVE-2025-6180HIGH8.5The StrongDM Client insufficiently protected a pre-authentication token. Attackers could exploit this to intercept and r...
CVE-2025-28041HIGH8.6Incorrect access control in the doFilter function of itranswarp up to 2.19 allows attackers to access sensitive componen...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now