2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-51087HIGH8.6Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/saveParentControlInfo. The manipulation of...
CVE-2025-33109HIGH8.8IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to a privilege escalation caused by an invalid database authority check....
CVE-2025-7695HIGH8.8The Dataverse Integration plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks...
CVE-2025-7640HIGH8.1The hiWeb Export Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2025-26397HIGH7.8SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vuln...
CVE-2025-54365HIGH7.5fastapi-guard is a security library for FastAPI that provides middleware to control IPs, log requests, detect penetratio...
CVE-2025-54377HIGH7.8Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.23.18 and below, RooCode d...
CVE-2025-53942HIGH7.4authentik is an open-source Identity Provider that emphasizes flexibility and versatility, with support for a wide set o...
CVE-2025-53537HIGH7.5LibHTP is a security-aware parser for the HTTP protocol and its related bits and pieces. In versions 0.5.50 and below, t...
CVE-2025-47281HIGH7.7Kyverno is a policy engine designed for cloud native platform engineering teams. In versions 1.14.1 and below, a Denial ...
CVE-2025-47187HIGH7.5A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and th...
CVE-2025-8069HIGH7.8During the AWS Client VPN client installation on Windows devices, the install process references the C:\usr\local\window...
CVE-2025-2634HIGH7.8Out of bounds read vulnerability due to improper bounds checking in NI LabVIEW in fontmgr may result in information disc...
CVE-2025-2633HIGH7.8Out of bounds read vulnerability due to improper bounds checking in NI LabVIEW in lvre!UDecStrToNum that may result in i...
CVE-2025-6018HIGH7.8A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication...
CVE-2025-40597HIGH7.5A Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to...
CVE-2025-40596HIGH7.3A Stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker t...
CVE-2025-33077HIGH8.8IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 is vulnerable to a stack-based buffer overflow, caused b...
CVE-2025-33076HIGH8.8IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 is vulnerable to a stack-based buffer overflow, caused b...
CVE-2025-33020HIGH7.5IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 transmits sensitive information without encryption that ...
CVE-2025-46099HIGH7.2In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module direc...
CVE-2025-54297HIGH7A stored XSS vulnerability in CComment component 5.0.0-6.1.14 for Joomla was discovered.
CVE-2025-54296HIGH7A stored XSS vulnerability in ProFiles component 1.0-1.5.0 for Joomla was discovered.
CVE-2025-50127HIGH8.5A SQLi vulnerability in DJ-Flyer component 1.0-3.2 for Joomla was discovered. The issue allows privileged users to execu...
CVE-2025-41684HIGH8.8An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now