2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-70249HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizard2.
CVE-2025-70247HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizard1.
CVE-2025-70246HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formVirtualServ.
CVE-2025-70242HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formSetWanPPTP.
CVE-2025-70227HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the nextPage parameter to goform/formLanguageChange.
CVE-2025-48611HIGH7.8In DeviceId of DeviceId.java, there is a possible desync in persistence due to a missing bounds check. This could lead t...
CVE-2025-13219HIGH7.5IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive information in URL parameters. This may lead to information...
CVE-2025-68648HIGH7.2A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer ...
CVE-2025-66178HIGH7.2A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F...
CVE-2025-56421HIGH7.5SQL Injection vulnerability in LimeSurvey before v.6.15.4+250710 allows a remote attacker to obtain sensitive informatio...
CVE-2025-54820HIGH8.1A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiM...
CVE-2025-54659HIGH7.5An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] vulnerability i...
CVE-2025-49784HIGH7.2An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiA...
CVE-2025-48418HIGH7.2A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, F...
CVE-2025-13957HIGH7.5CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause information disclosure and remote code exec...
CVE-2025-11739HIGH7.8CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administr...
CVE-2025-70028HIGH7.5An issue pertaining to CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') was discov...
CVE-2025-70031HIGH8.8An issue pertaining to CWE-352: Cross-Site Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.
CVE-2025-70030HIGH7.5An issue pertaining to CWE-1333: Inefficient Regular Expression Complexity (4.19) was discovered in Sunbird-Ed SunbirdEd...
CVE-2025-68402HIGH8.2FreshRSS is a free, self-hostable RSS aggregator. From 57e1a37 - 00f2f04, the lengths of the nonce was changed from 40 c...
CVE-2025-62166HIGH7.5FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication...
CVE-2025-70038HIGH8.8An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in linagora Tw...
CVE-2025-70034HIGH7.5An issue pertaining to CWE-1333: Inefficient Regular Expression Complexity (4.19) was discovered in mscdex ssh2 v1.17.0.
CVE-2025-15568HIGH8A command injection vulnerability was identified in the web module of Archer AXE75 v1.6/v1.0 router. An authenticated a...
CVE-2025-70048HIGH7.5An issue pertaining to CWE-319: Cleartext Transmission of Sensitive Information was discovered in Nexusoft NexusInterfac...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now