2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-6627HIGH8.8A vulnerability has been found in TOTOLINK A702R 4.0.0-B20230721.1521 and classified as critical. This vulnerability aff...
CVE-2025-6678HIGH7.5Autel MaxiCharger AC Wallbox Commercial PIN Missing Authentication Information Disclosure Vulnerability. This vulnerabil...
CVE-2025-6445HIGH8.1ServiceStack FindType Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attacker...
CVE-2025-5834HIGH7.8Pioneer DMH-WT7600NEX Missing Immutable Root of Trust in Hardware Local Privilege Escalation Vulnerability. This vulnera...
CVE-2025-5830HIGH8.8Autel MaxiCharger AC Wallbox Commercial DLB_SlaveRegister Heap-based Buffer Overflow Remote Code Execution Vulnerability...
CVE-2025-5827HIGH8.8Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Stack-based Buffer Overflow Remote Code Execution Vulnerab...
CVE-2025-5825HIGH7.5Autel MaxiCharger AC Wallbox Commercial Firmware Downgrade Remote Code Execution Vulnerability. This vulnerability allow...
CVE-2025-5824HIGH7.5Autel MaxiCharger AC Wallbox Commercial Origin Validation Error Authentication Bypass Vulnerability. This vulnerability ...
CVE-2025-5822HIGH8.8Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This ...
CVE-2025-45332HIGH7.5vkoskiv c-ray 1.1 contains a Null Pointer Dereference (NPD) vulnerability in the parse_mtllib function of its data proce...
CVE-2025-6617HIGH8.8A vulnerability was found in D-Link DIR-619L 2.06B01 and classified as critical. This issue affects the function formAdv...
CVE-2025-6616HIGH8.8A vulnerability has been found in D-Link DIR-619L 2.06B01 and classified as critical. This vulnerability affects the fun...
CVE-2025-5015HIGH8.8A cross-site scripting vulnerability exists in the AccuWeather and Custom RSS widget that allows an unauthenticated user...
CVE-2025-52999HIGH8.7jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Pr...
CVE-2025-52894HIGH7.5OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certifi...
CVE-2025-52890HIGH8.1Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus vers...
CVE-2025-49152HIGH8.7The affected products contain JSON Web Tokens (JWT) that do not expire, which could allow an attacker to gain access to ...
CVE-2025-6615HIGH8.8A vulnerability, which was classified as critical, was found in D-Link DIR-619L 2.06B01. This affects the function formA...
CVE-2025-6614HIGH8.8A vulnerability, which was classified as critical, has been found in D-Link DIR-619L 2.06B01. Affected by this issue is ...
CVE-2025-52479HIGH7.7HTTP.jl provides HTTP client and server functionality for Julia, and URIs.jl parses and works with Uniform Resource Iden...
CVE-2025-49845HIGH7.5Discourse is an open-source discussion platform. The visibility of posts typed `whisper` is controlled via the `whispers...
CVE-2025-25905HIGH7.1Cross-Site Scripting (XSS) vulnerability in CADClick v1.13.0 and before allows remote attackers to inject arbitrary web ...
CVE-2025-6610HIGH7.2A vulnerability was found in itsourcecode Employee Management System up to 1.0. It has been classified as critical. This...
CVE-2025-6609HIGH8.8A vulnerability was found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected by thi...
CVE-2025-6608HIGH8.8A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected b...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now