2025 CVE Vulnerabilities

45,168 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-9007HIGH8.8A vulnerability has been found in Tenda CH22 1.0.0.1. Affected by this issue is the function formeditFileName of the fil...
CVE-2025-9006HIGH8.8A vulnerability was identified in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function formdelFileName of ...
CVE-2025-9001HIGH7.5A vulnerability was determined in LemonOS up to nightly-2024-07-12 on LemonOS. Affected by this issue is the function HT...
CVE-2025-8342HIGH8.1The WooCommerce OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypas...
CVE-2025-6025HIGH7.5The Order Tip for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Improper Input Validation in all ver...
CVE-2025-9000HIGH7A vulnerability was found in Mechrevo Control Center GX V2 5.56.51.48. Affected by this vulnerability is an unknown func...
CVE-2025-31987HIGH7.5HCL Connections Docs may mishandle validation of certain uploaded documents leading to denial of service due to resource...
CVE-2025-8978HIGH8.1A vulnerability was determined in D-Link DIR-619L 6.02CN02. Affected is the function FirmwareUpgrade of the component bo...
CVE-2025-55708HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech System...
CVE-2025-53587HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in ApusTheme Findgo findgo allows Cross Site Request Forgery.This issue ...
CVE-2025-53575HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in primersoftware Pri...
CVE-2025-52797HIGH8.2Cross-Site Request Forgery (CSRF) vulnerability in josepsitjar StoryMap wp-storymap allows SQL Injection.This issue affe...
CVE-2025-52765HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in lisensee NetInsight Analytics Implementation Plugin netinsight-analyt...
CVE-2025-51986HIGH7.5An issue was discovered in the demo/LINUXTCP implementation of cwalter-at freemodbus v.2018-09-12 allowing attackers to ...
CVE-2025-55195HIGH7.3@std/toml is the Deno Standard Library. Prior to version 1.0.9, an attacker can pollute the prototype chain in Node.js r...
CVE-2025-55192HIGH8.6HomeAssistant-Tapo-Control offers Control for Tapo cameras as a Home Assistant component. Prior to commit 2a3b80f, there...
CVE-2025-20263HIGH8.6A vulnerability in the web services interface of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Ci...
CVE-2025-20253HIGH8.6A vulnerability in the IKEv2 feature of Cisco IOS Software, IOS XE Software, Secure Firewall ASA Software, and Secure FT...
CVE-2025-20251HIGH8.5A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Softwar...
CVE-2025-20244HIGH7.7A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Softwar...
CVE-2025-20243HIGH8.6A vulnerability in the management and VPN web servers of Cisco Secure Firewall ASA Software and Secure FTD Software coul...
CVE-2025-20239HIGH8.6A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE Software, Secure Fi...
CVE-2025-20222HIGH8.6A vulnerability in the RADIUS proxy feature for the IPsec VPN feature of Cisco Secure Firewall Adaptive Security Applian...
CVE-2025-20217HIGH8.6A vulnerability in the packet inspection functionality of the Snort 3 Detection Engine of Cisco Secure Firewall Threat D...
CVE-2025-20148HIGH8.5A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could al...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now