2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-41683HIGH8.8An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of ...
CVE-2025-31701HIGH8.1A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending sp...
CVE-2025-31700HIGH8.1A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending sp...
CVE-2025-54441HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje...
CVE-2025-54439HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje...
CVE-2025-8021HIGH7.7All versions of the package files-bucket-server are vulnerable to Directory Traversal where an attacker can traverse the...
CVE-2025-8020HIGH8.2All versions of the package private-ip are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provid...
CVE-2025-7722HIGH8.8The Social Streams plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0....
CVE-2025-6190HIGH8.8The Realty Portal – Agent plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within...
CVE-2025-8060HIGH8.8A vulnerability has been found in Tenda AC23 16.03.07.52 and classified as critical. Affected by this vulnerability is t...
CVE-2025-43022HIGH7.2A potential SQL injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. T...
CVE-2025-8011HIGH8.8Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corr...
CVE-2025-8010HIGH8.8Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corr...
CVE-2025-7766HIGH8.6Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network d...
CVE-2025-54141HIGH7.5ViewVC is a browser interface for CVS and Subversion version control repositories. In versions 1.1.0 through 1.1.31 and ...
CVE-2025-54140HIGH7.5pyLoad is a free and open-source Download Manager written in pure Python. In version 0.5.0b3.dev89, an authenticated pat...
CVE-2025-54138HIGH7.5LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of netwo...
CVE-2025-54137HIGH7.3HAX CMS NodeJS allows users to manage their microsite universe with a NodeJS backend. Versions 11.0.9 and below were dis...
CVE-2025-54072HIGH8.1yt-dlp is a feature-rich command-line audio/video downloader. In versions 2025.06.25 and below, when the --exec option i...
CVE-2025-53703HIGH8.7DuraComm SPM-500 DP-10iN-100-MU transmits sensitive data without encryption over a channel that could be intercepted b...
CVE-2025-53538HIGH7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-48733HIGH8.7DuraComm SPM-500 DP-10iN-100-MU lacks access controls for a function that should require user authentication. This cou...
CVE-2025-41425HIGH8.1DuraComm SPM-500 DP-10iN-100-MU is vulnerable to a cross-site scripting attack. This could allow an attacker to preven...
CVE-2025-8040HIGH8.8Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these b...
CVE-2025-8039HIGH8.1In some cases search terms persisted in the URL bar even after navigating away from the search page. This vulnerability ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now