2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-9120HIGH8.6Improper Control of Generation of Code ('Code Injection') vulnerability in OpenText™ Carbonite Safe Server Backup allows...
CVE-2025-69252HIGH7.5free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile co...
CVE-2025-69250HIGH7.5free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile co...
CVE-2025-69248HIGH7.5free5GC is an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 of fr...
CVE-2025-69247HIGH7.5free5GC go-upf is the User Plane Function (UPF) implementation for 5G networks that is part of the free5GC project. Vers...
CVE-2025-69232HIGH7.5free5GC is an open-source project for 5th generation (5G) mobile core networks. free5GC go-upf versions up to and includ...
CVE-2025-71056HIGH8.1Improper session management in GCOM EPON 1GE ONU version C00R371V00B01 allows attackers to execute a session hijacking a...
CVE-2025-70328HIGH8.8TOTOLINK X6000R v9.4.0cu.1498_B20250826 contains an OS command injection vulnerability in the NTPSyncWithHost handler of...
CVE-2025-70329HIGH8TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the ...
CVE-2025-67733HIGH7.1Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use ...
CVE-2025-63946HIGH7.4A privilege escalation (PE) vulnerability in the Tencent PC Manager app thru 17.10.28554.205 on Windows devices enables ...
CVE-2025-63945HIGH7.4A privilege escalation (PE) vulnerability in the Tencent iOA app thru 210.9.28693.621001 on Windows devices enables a lo...
CVE-2025-61144HIGH7.3libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function.
CVE-2025-70058HIGH7.4An issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0. The application dis...
CVE-2025-70045HIGH7.4An issue pertaining to CWE-295: Improper Certificate Validation was discovered in jxcore jxm master. The application dis...
CVE-2025-14905HIGH7.2A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callbac...
CVE-2025-69700HIGH7.5Tenda FH1203 V2.0.1.6 contains a stack-based buffer overflow vulnerability in the modify_add_client_prio function, which...
CVE-2025-15582HIGH8.1A security flaw has been discovered in detronetdip E-commerce 1.0.0. The impacted element is the function Delete/Update ...
CVE-2025-69410HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-69409HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-69408HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-69407HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-69406HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-69402HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-69401HIGH7.5Authentication Bypass by Spoofing vulnerability in mdalabar WooODT Lite byconsole-woo-order-delivery-time allows Identit...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now