2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-7932HIGH8.8A vulnerability classified as critical has been found in D-Link DIR‑817L up to 1.04B01. This affects the function lxmldb...
CVE-2025-7931HIGH7.3A vulnerability was found in code-projects Church Donation System 1.0. It has been rated as critical. Affected by this i...
CVE-2025-7717HIGH7.5Missing Authorization vulnerability in Drupal File Download allows Forceful Browsing.This issue affects File Download: f...
CVE-2025-54082HIGH8.1marshmallow-packages/nova-tiptap is a rich text editor for Laravel Nova based on tiptap. Prior to 5.7.0, a vulnerability...
CVE-2025-44653HIGH7.5In H3C GR2200 MiniGR1A0V100R016, the USERLIMIT_GLOBAL option is set to 0 in the /etc/bftpd.conf. This can cause DoS atta...
CVE-2025-44649HIGH7.5In the configuration file of racoon in the TRENDnet TEW-WLC100P 2.03b03, the first item of exchage_mode is set to aggres...
CVE-2025-44651HIGH7.5In TRENDnet TPL-430AP FW1.0, the USERLIMIT_GLOBAL option is set to 0 in the bftpd-related configuration file. This can c...
CVE-2025-44650HIGH7.5In Netgear R7000 V1.3.1.64_10.1.36 and EAX80 V1.0.1.70_1.0.2, the USERLIMIT_GLOBAL option is set to 0 in the bftpd.conf ...
CVE-2025-44647HIGH7.3In TRENDnet TEW-WLC100P 2.03b03, the i_dont_care_about_security_and_use_aggressive_mode_psk option is enabled in the str...
CVE-2025-7927HIGH8.8A vulnerability has been found in PHPGurukul Online Banquet Booking System 1.0 and classified as critical. This vulnerab...
CVE-2025-46123HIGH7.2An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDir...
CVE-2025-46116HIGH8.8An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDir...
CVE-2025-7382HIGH8.8A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjac...
CVE-2025-4130HIGH7.5Use of Hard-coded Credentials vulnerability in PAVO Inc. PAVO Pay allows Read Sensitive Constants Within an Executable. ...
CVE-2025-4129HIGH7.5Authorization Bypass Through User-Controlled Key vulnerability in PAVO Inc. PAVO Pay allows Exploitation of Trusted Iden...
CVE-2025-4040HIGH7.1Authorization Bypass Through User-Controlled Key vulnerability in Turpak Automatic Station Monitoring System allows Priv...
CVE-2025-30192HIGH7.5An attacker spoofing answers to ECS enabled requests sent out by the Recursor has a chance of success higher than non-EC...
CVE-2025-41459HIGH7.8Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App St...
CVE-2025-50151HIGH8.8File access paths in configuration files uploaded by users with administrator access are not validated. This issue affe...
CVE-2025-49656HIGH7.5Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affe...
CVE-2025-41679HIGH7.5An unauthenticated remote attacker could exploit a buffer overflow vulnerability in the device causing a denial of servi...
CVE-2025-41678HIGH7.2A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization ...
CVE-2025-41675HIGH7.2A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communicati...
CVE-2025-41674HIGH7.2A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due t...
CVE-2025-41673HIGH7.2A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms action due to ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now