2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-55587HIGH7.5TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the hostname parameter at /boafrm/f...
CVE-2025-55586HIGH7.5TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the url parameter at /boafrm/formFi...
CVE-2025-53192HIGH8.8** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons...
CVE-2025-4371HIGH7A potential vulnerability was reported in the Lenovo 510 FHD and Performance FHD web cameras that could allow an attacke...
CVE-2025-32992HIGH8.5Thermo Fisher Scientific ePort through 3.0.0 has Incorrect Access Control.
CVE-2025-55300HIGH8.6Komari is a lightweight, self-hosted server monitoring tool designed to provide a simple and efficient solution for moni...
CVE-2025-55291HIGH7.1Shaarli is a minimalist bookmark manager and link sharing service. Prior to 0.15.0, the input string in the cloud tag pa...
CVE-2025-55283HIGH7.2aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that...
CVE-2025-55282HIGH7.2aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that...
CVE-2025-55201HIGH8.5Copier library and CLI app for rendering project templates. Prior to 9.9.1, a safe template can currently read and write...
CVE-2025-4962HIGH7.7An Insecure Direct Object Reference (IDOR) vulnerability was identified in the `POST /v1/templates` endpoint of the Luna...
CVE-2025-36120HIGH8.8IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH s...
CVE-2025-33100HIGH7.5IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cryptographic key, whi...
CVE-2025-33090HIGH7.5IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to cause a denial of service using a specially cr...
CVE-2025-1759HIGH7.5IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated me...
CVE-2025-47206HIGH8.1An out-of-bounds write vulnerability has been reported to affect File Station 5. If a remote attacker gains a user accou...
CVE-2025-5296HIGH7.3CWE-59: Improper Link Resolution Before File Access ('Link Following') vulnerability exists that could cause arbitrary ...
CVE-2025-6625HIGH8.7CWE-20: Improper Input Validation vulnerability exists that could cause a Denial Of Service when specific crafted FTP co...
CVE-2025-31713HIGH8.4In engineer mode service, there is a possible command injection due to improper input validation. This could lead to loc...
CVE-2025-7342HIGH7.5A security issue was discovered in the Kubernetes Image Builder where default credentials are enabled during the Windows...
CVE-2025-9091HIGH7.8A security flaw has been discovered in Tenda AC20 16.03.08.12. Affected by this vulnerability is an unknown functionalit...
CVE-2025-8142HIGH8.8The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.6.7 via th...
CVE-2025-8105HIGH7.3The The Soledad theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including,...
CVE-2025-38552HIGH7.8In the Linux kernel, the following vulnerability has been resolved: mptcp: plug races between subflow fail and subflow ...
CVE-2025-38550HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Delay put pmc->idev in mld_del_delrec(...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now