2025 CVE Vulnerabilities

45,343 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-41675HIGH7.2A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communicati...
CVE-2025-41674HIGH7.2A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due t...
CVE-2025-41673HIGH7.2A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms action due to ...
CVE-2025-1469HIGH7.5Authorization Bypass Through User-Controlled Key vulnerability in Turtek Software Eyotek allows Exploitation of Trusted ...
CVE-2025-4569HIGH7.7An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token t...
CVE-2025-4049HIGH8.6Use of hard-coded, the same among all vulnerable installations SQLite credentials vulnerability in SIGNUM-NET FARA allow...
CVE-2025-7919HIGH7.1WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability, allowing unauthenticated remot...
CVE-2025-7344HIGH8.8The EAI developed by Digiwin has a Privilege Escalation vulnerability, allowing remote attackers with regular privileges...
CVE-2025-24938HIGH8.4The web application allows user input to pass unfiltered to a command executed on the underlying operating system. An at...
CVE-2025-7917HIGH8.6WinMatrix3 Web package developed by Simopro Technology has an Arbitrary File Upload vulnerability, allowing remote attac...
CVE-2025-7914HIGH8.8A vulnerability has been found in Tenda AC6 15.03.06.50 and classified as critical. Affected by this vulnerability is th...
CVE-2025-7913HIGH8.8A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. Affected is the funct...
CVE-2025-7912HIGH8.8A vulnerability, which was classified as critical, has been found in TOTOLINK T6 4.1.5cu.748_B20211015. This issue affec...
CVE-2025-7910HIGH8.8A vulnerability classified as critical has been found in D-Link DIR-513 1.10. This affects the function sprintf of the f...
CVE-2025-7909HIGH8.8A vulnerability was found in D-Link DIR-513 1.0. It has been rated as critical. Affected by this issue is the function s...
CVE-2025-7908HIGH8.8A vulnerability was found in D-Link DI-8100 1.0. It has been declared as critical. Affected by this vulnerability is the...
CVE-2025-7905HIGH8.8A vulnerability has been found in itsourcecode Insurance Management System 1.0 and classified as critical. This vulnerab...
CVE-2025-54317HIGH8.4An issue was discovered in Logpoint before 7.6.0. An attacker with operator privileges can exploit a path traversal vuln...
CVE-2025-48965HIGH7.5Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_named_data can trigger conflicting data ...
CVE-2025-7904HIGH8.8A vulnerability, which was classified as critical, was found in itsourcecode Insurance Management System 1.0. This affec...
CVE-2025-7898HIGH7.2A vulnerability was found in Codecanyon iDentSoft 2.0. It has been classified as critical. This affects an unknown part ...
CVE-2025-7896HIGH7.5A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this v...
CVE-2025-46385HIGH8.6CWE-918 Server-Side Request Forgery (SSRF)
CVE-2025-46384HIGH8.8CWE-434 Unrestricted Upload of File with Dangerous Type
CVE-2025-7886HIGH7.3A vulnerability, which was classified as critical, was found in pmTicket Project-Management-Software up to 2ef379da2075f...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now