2025 CVE Vulnerabilities

45,181 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14104MEDIUM6.1A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, spe...
CVE-2025-14094CRITICAL9.8A flaw has been found in Edimax BR-6478AC V3 1.0.15. The affected element is the function sub_44CCE4 of the file /boafrm...
CVE-2025-14093CRITICAL9.8A vulnerability was detected in Edimax BR-6478AC V3 1.0.15. Impacted is the function sub_416990 of the file /boafrm/form...
CVE-2025-66418HIGH7.5urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of li...
CVE-2025-65897HIGH8.8zdh_web is a data collection, processing, monitoring, scheduling, and management platform. In zdh_web thru 5.6.17, insuf...
CVE-2025-65730HIGH8.8Authentication Bypass via Hardcoded Credentials GoAway up to v0.62.18, fixed in 0.62.19, uses a hardcoded secret for sig...
CVE-2025-64056MEDIUM4.3File upload vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store arbit...
CVE-2025-64054CRITICAL9.6A reflected Cross Site Scripting (XSS) vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial o...
CVE-2025-64053HIGH7.5A Buffer overflow vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial of service or potentia...
CVE-2025-64052MEDIUM5.1An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to execute arb...
CVE-2025-14092HIGH7.2A security vulnerability has been detected in Edimax BR-6478AC V3 1.0.15. This issue affects the function sub_416898 of ...
CVE-2025-14091HIGH7.3A weakness has been identified in TrippWasTaken PHP-Guitar-Shop up to 6ce0868889617c1975982aae6df8e49555d0d555. This vul...
CVE-2025-14090HIGH7.2A security flaw has been discovered in AMTT Hotel Broadband Operation System 1.0. This affects an unknown part of the fi...
CVE-2025-14089MEDIUM6.3A vulnerability was identified in Himool ERP up to 2.2. Affected by this issue is the function update_account of the fil...
CVE-2025-64057HIGH8.3Directory traversal vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to sto...
CVE-2025-14088MEDIUM6.3A vulnerability was determined in ketr JEPaaS up to 7.2.8. Affected by this vulnerability is an unknown functionality of...
CVE-2025-58098HIGH8.3Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the ...
CVE-2025-14086HIGH8.8A vulnerability was found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is an unknown function of the file /app-api/v1...
CVE-2025-14085HIGH8.8A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. This impacts an unknown function of the file /app-...
CVE-2025-6966MEDIUM5.5NULL pointer dereference in TagSection.keys() in python-apt on APT-based Linux systems allows a local attacker to cause ...
CVE-2025-13654HIGH7.5A stack buffer overflow vulnerability exists in the buffer_get function of duc, a disk management tool, where a conditio...
CVE-2025-66200MEDIUM5.4mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the R...
CVE-2025-65082MEDIUM6.5Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment va...
CVE-2025-59775HIGH7.5Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and M...
CVE-2025-55753HIGH7.5An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in defaul...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now