2025 CVE Vulnerabilities

45,343 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-44652HIGH7.5In Netgear RAX30 V1.0.10.94_3, the USERLIMIT_GLOBAL option is set to 0 in multiple bftpd-related configuration files. Th...
CVE-2025-36845HIGH8.6An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php allows for Server-Side...
CVE-2025-36107HIGH7.5IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to obtain sensitive information due ...
CVE-2025-7932HIGH8.8A vulnerability classified as critical has been found in D-Link DIR‑817L up to 1.04B01. This affects the function lxmldb...
CVE-2025-7931HIGH7.3A vulnerability was found in code-projects Church Donation System 1.0. It has been rated as critical. Affected by this i...
CVE-2025-7717HIGH7.5Missing Authorization vulnerability in Drupal File Download allows Forceful Browsing.This issue affects File Download: f...
CVE-2025-54082HIGH8.1marshmallow-packages/nova-tiptap is a rich text editor for Laravel Nova based on tiptap. Prior to 5.7.0, a vulnerability...
CVE-2025-44653HIGH7.5In H3C GR2200 MiniGR1A0V100R016, the USERLIMIT_GLOBAL option is set to 0 in the /etc/bftpd.conf. This can cause DoS atta...
CVE-2025-44649HIGH7.5In the configuration file of racoon in the TRENDnet TEW-WLC100P 2.03b03, the first item of exchage_mode is set to aggres...
CVE-2025-44651HIGH7.5In TRENDnet TPL-430AP FW1.0, the USERLIMIT_GLOBAL option is set to 0 in the bftpd-related configuration file. This can c...
CVE-2025-44650HIGH7.5In Netgear R7000 V1.3.1.64_10.1.36 and EAX80 V1.0.1.70_1.0.2, the USERLIMIT_GLOBAL option is set to 0 in the bftpd.conf ...
CVE-2025-44647HIGH7.3In TRENDnet TEW-WLC100P 2.03b03, the i_dont_care_about_security_and_use_aggressive_mode_psk option is enabled in the str...
CVE-2025-7927HIGH8.8A vulnerability has been found in PHPGurukul Online Banquet Booking System 1.0 and classified as critical. This vulnerab...
CVE-2025-46123HIGH7.2An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDir...
CVE-2025-46116HIGH8.8An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDir...
CVE-2025-7382HIGH8.8A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjac...
CVE-2025-4130HIGH7.5Use of Hard-coded Credentials vulnerability in PAVO Inc. PAVO Pay allows Read Sensitive Constants Within an Executable. ...
CVE-2025-4129HIGH7.5Authorization Bypass Through User-Controlled Key vulnerability in PAVO Inc. PAVO Pay allows Exploitation of Trusted Iden...
CVE-2025-4040HIGH7.1Authorization Bypass Through User-Controlled Key vulnerability in Turpak Automatic Station Monitoring System allows Priv...
CVE-2025-30192HIGH7.5An attacker spoofing answers to ECS enabled requests sent out by the Recursor has a chance of success higher than non-EC...
CVE-2025-41459HIGH7.8Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App St...
CVE-2025-50151HIGH8.8File access paths in configuration files uploaded by users with administrator access are not validated. This issue affe...
CVE-2025-49656HIGH7.5Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affe...
CVE-2025-41679HIGH7.5An unauthenticated remote attacker could exploit a buffer overflow vulnerability in the device causing a denial of servi...
CVE-2025-41678HIGH7.2A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now