2025 CVE Vulnerabilities

45,181 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-66506HIGH7.5Fulcio is a free-to-use certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identit...
CVE-2025-66238HIGH7.4DCIM dcTrack allows an attacker to misuse certain remote access features. An authenticated user with access to the appli...
CVE-2025-65900MEDIUM6.5Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due...
CVE-2025-65899MEDIUM5.3Kalmia CMS version 0.2.0 contains a user enumeration vulnerability in its authentication mechanism. The application retu...
CVE-2025-53704HIGH8.7The password reset mechanism for the Pivot client application is weak, and it may allow an attacker to take over the acc...
CVE-2025-1910MEDIUM6.3The WatchGuard Mobile VPN with SSL Client on Windows allows a locally authenticated non-administrative Windows user to e...
CVE-2025-1547HIGH7.2A stack-based buffer overflow vulnerability [CWE-121] in WatchGuard Fireware OS's certificate request command could allo...
CVE-2025-1545HIGH7.5An XPath Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensi...
CVE-2025-13940MEDIUM5.5An Expected Behavior Violation [CWE-440] vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fir...
CVE-2025-13939MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2025-13938MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2025-13937MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2025-13936MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2025-13932HIGH8.3The SolisCloud API suffers from a Broken Access Control vulnerability, specifically an Insecure Direct Object Reference ...
CVE-2025-12986MEDIUM6When a WF200/WGM160P device is configured to operate as an Access Point, it may be vulnerable to a denial of service tri...
CVE-2025-12196HIGH7.2An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to exe...
CVE-2025-12195HIGH7.2An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to exe...
CVE-2025-12026HIGH7.2An Out-of-bounds Write vulnerability in WatchGuard Fireware OS’s certificate request command could allow an authenticate...
CVE-2025-11838HIGH7.5A memory corruption vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker to trigger a Denial of...
CVE-2025-10285HIGH7.4The web interface of the Silicon Labs Simplicity Device Manager is exposed publicly and can be used to extract the NTLMv...
CVE-2025-66576CRITICAL9.8Remote Keyboard Desktop 1.0.1 enables remote attackers to execute system commands via the rundll32.exe exported function...
CVE-2025-66575HIGH7.8VeeVPN 1.6.1 contains an unquoted service path vulnerability in the VeePNService that allows remote attackers to execute...
CVE-2025-66574MEDIUM5.4TranzAxis 3.2.41.10.26 allows authenticated users to inject cross-site scripting via the `Open Object in Tree` endpoint,...
CVE-2025-66573HIGH7.5Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive info...
CVE-2025-66572MEDIUM6.9Loaded Commerce 6.6 contains a client-side template injection vulnerability via the search parameter that allows unauthe...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now