2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-6130HIGH8.8A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This issue...
CVE-2025-6129HIGH8.8A vulnerability classified as critical was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This vulnerability affects ...
CVE-2025-6128HIGH8.8A vulnerability classified as critical has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This affects an unknow...
CVE-2025-49795HIGH7.5A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an...
CVE-2025-49125HIGH7.5Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat.  When using PreResources or Pos...
CVE-2025-49124HIGH8.4Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer fo...
CVE-2025-48988HIGH7.5Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: ...
CVE-2025-48976HIGH7.5Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons Fil...
CVE-2025-3526HIGH7.5SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 2...
CVE-2025-3602HIGH7.5Liferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through update 92, 7.3 GA thr...
CVE-2025-36632HIGH7.8In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could execute c...
CVE-2025-6122HIGH8.8A vulnerability, which was classified as critical, was found in code-projects Restaurant Order System 1.0. This affects ...
CVE-2025-5689HIGH8.5A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the fir...
CVE-2025-6115HIGH8.8A vulnerability was found in D-Link DIR-619L 2.06B01 and classified as critical. Affected by this issue is the function ...
CVE-2025-6114HIGH8.8A vulnerability has been found in D-Link DIR-619L 2.06B01 and classified as critical. Affected by this vulnerability is ...
CVE-2025-40728HIGH8.8SQL injection vulnerability in Customer Support System v1.0. This vulnerability allows an authenticated attacker to retr...
CVE-2025-3464HIGH8.4A race condition vulnerability exists in Armoury Crate. This vulnerability arises from a Time-of-check Time-of-use issue...
CVE-2025-6113HIGH8.8A vulnerability, which was classified as critical, was found in Tenda FH1203 2.0.1.6. Affected is the function fromadvse...
CVE-2025-6112HIGH8.8A vulnerability, which was classified as critical, has been found in Tenda FH1205 2.0.0.7. This issue affects the functi...
CVE-2025-4987HIGH8.7A stored Cross-site Scripting (XSS) vulnerability affecting Opportunity Management in Project Portfolio Manager from Rel...
CVE-2025-6111HIGH8.8A vulnerability classified as critical was found in Tenda FH1205 2.0.0.7(775). This vulnerability affects the function f...
CVE-2025-6110HIGH8.8A vulnerability classified as critical has been found in Tenda FH1201 1.2.0.14(408). This affects an unknown part of the...
CVE-2025-6105HIGH8.8A vulnerability has been found in jflyfox jfinal_cms 5.0.1 and classified as problematic. This vulnerability affects unk...
CVE-2025-6104HIGH8.8A vulnerability, which was classified as critical, was found in Wifi-soft UniBox Controller up to 20250506. This affects...
CVE-2025-6103HIGH8.8A vulnerability, which was classified as critical, has been found in Wifi-soft UniBox Controller up to 20250506. Affecte...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now