2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-6319HIGH8.8A vulnerability, which was classified as critical, has been found in PHPGurukul Pre-School Enrollment System 1.0. This i...
CVE-2025-6309HIGH8.8A vulnerability classified as critical was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected by this v...
CVE-2025-6308HIGH8.8A vulnerability classified as critical has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected is a...
CVE-2025-6302HIGH8.8A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is the...
CVE-2025-6292HIGH8.8A vulnerability has been found in D-Link DIR-825 2.03 and classified as critical. This vulnerability affects the functio...
CVE-2025-6291HIGH8.8A vulnerability, which was classified as critical, was found in D-Link DIR-825 2.03. This affects the function do_file o...
CVE-2025-49715HIGH7.5Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows...
CVE-2025-47771HIGH8.1PowSyBl (Power System Blocks) is a framework to build power system oriented software. In versions 6.3.0 to 6.7.1, there ...
CVE-2025-6283HIGH7.5A vulnerability was found in xataio Xata Agent up to 0.3.0. It has been classified as problematic. This affects the func...
CVE-2025-6279HIGH8A vulnerability, which was classified as critical, has been found in Upsonic up to 0.55.6. This issue affects the functi...
CVE-2025-33121HIGH7.1IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 is vulnerable to an XML external entity injection (XXE) attack when...
CVE-2025-52464HIGH8.3Meshtastic is an open source mesh networking solution. In versions from 2.5.0 to before 2.6.11, the flashing procedure o...
CVE-2025-6019HIGH7A Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally, the "allow_active" setting in Polk...
CVE-2025-5071HIGH8.8The AI Engine plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing ...
CVE-2025-49763HIGH7.5ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if maliciou...
CVE-2025-31698HIGH7.5ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users ...
CVE-2025-23173HIGH7.5The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the D...
CVE-2025-23172HIGH7.2The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP e...
CVE-2025-23171HIGH7.2The Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director...
CVE-2025-23168HIGH8.8The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OT...
CVE-2025-23121HIGH8.8A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user
CVE-2025-6192HIGH8.8Use after free in Metrics in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially exploit heap...
CVE-2025-6191HIGH8.8Integer overflow in V8 in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially perform out of ...
CVE-2025-29646HIGH7.1An issue in upf in open5gs 2.7.2 and earlier allows a remote attacker to cause a Denial of Service via a crafted PFCP Se...
CVE-2025-20271HIGH8.6A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devic...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now