2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-34128HIGH8.6A buffer overflow vulnerability exists in the X360 VideoPlayer ActiveX control (VideoPlayer.ocx) version 2.6 when handli...
CVE-2025-34126HIGH8.7A path traversal vulnerability exists in RIPS Scanner version 0.54. The vulnerability allows remote attackers to read ar...
CVE-2025-34124HIGH8.4A buffer overflow vulnerability exists in Heroes of Might and Magic III Complete 4.0.0.0, HD Mod 3.808 build 9, and Demo...
CVE-2025-34123HIGH8.4A stack-based buffer overflow vulnerability exists in VideoCharge Studio 2.12.3.685 when processing a specially crafted ...
CVE-2025-34120HIGH8.7An unauthenticated file download vulnerability exists in LimeSurvey versions from 2.0+ up to and including 2.06+ Build 1...
CVE-2025-34119HIGH8.8A remote file disclosure vulnerability exists in EasyCafe Server 2.2.14, exploitable by unauthenticated remote attackers...
CVE-2025-34118HIGH8.7A path traversal vulnerability exists in Linknat VOS Manager versions prior to 2.1.9.07, including VOS2009 and early VOS...
CVE-2025-53908HIGH8.3RomM is a self-hosted rom manager and player. Versions prior to 3.10.3 and 4.0.0-beta.3 have an authenticated path trave...
CVE-2025-40777HIGH7.5If a `named` caching resolver is configured with `serve-stale-enable` `yes`, and with `stale-answer-client-timeout` set ...
CVE-2025-36097HIGH7.5IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 are vulnerable t...
CVE-2025-20284HIGH7.2A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execut...
CVE-2025-20283HIGH7.2A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execut...
CVE-2025-20274HIGH8.8A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated,...
CVE-2025-7357HIGH8.7LITEON IC48A firmware versions prior to 01.00.19r and LITEON IC80A firmware versions prior to 01.01.12e store FTP-server...
CVE-2025-53943HIGH8.7VoidBot Open-Source is a customizable Discord bot. VoidBot Open-Source versions 0.0.1 through 0.8.1 contain a vulnerabil...
CVE-2025-53938HIGH7.5WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. An Authenticati...
CVE-2025-5994HIGH8.7A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in caching resolvers that sup...
CVE-2025-37104HIGH7.1A security vulnerability has been identified in HPE Telco Service Orchestrator software. The vulnerability could allow a...
CVE-2025-32874HIGH7.5An issue was discovered in Kaseya Rapid Fire Tools Network Detective through 2.0.16.0. A vulnerability exists in the Enc...
CVE-2025-32353HIGH8.2Kaseya Rapid Fire Tools Network Detective 2.0.16.0 has Unencrypted Credentials (for privileged access) stored in the col...
CVE-2025-40776HIGH8.6A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-pois...
CVE-2025-40923HIGH7.3Plack-Middleware-Session before version 0.35 for Perl generates session ids insecurely. The default session id generato...
CVE-2025-53757HIGH8.7This vulnerability exists in Digisol DG-GR6821AC Router due to misconfiguration of both Secure and HttpOnly flags on ses...
CVE-2025-53756HIGH8.7This vulnerability exists in Digisol DG-GR6821AC Router due to cleartext transmission of credentials in its web manageme...
CVE-2025-52819HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pakkemx Pakke Enví...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now