2025 CVE Vulnerabilities

45,191 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-59390CRITICAL9.8Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSign...
CVE-2025-13735HIGH7.4Out-of-bounds Read vulnerability in ASR1903、ASR3901 in ASR Lapwing_Linux on Linux (nr_fw modules). This vulnerability is...
CVE-2025-9558HIGH7.6There is a potential OOB Write vulnerability in the gen_prov_start function in pb_adv.c. The full length of the received...
CVE-2025-9557HIGH7.6‭An out-of-bound write can lead to an arbitrary code execution. Even on devices with some form of memory protection, thi...
CVE-2025-59820MEDIUM6.7In KDE Krita before 5.2.13, loading a manipulated TGA file could result in a heap-based buffer overflow in plugins/impex...
CVE-2025-55174LOW3.2In KDE Skanpage before 25.08.0, an attempt at file overwrite can result in the contents of the new file at the beginning...
CVE-2025-12061HIGH8.6The TAX SERVICE Electronic HDM WordPress plugin before 1.2.1 does not authorization and CSRF checks in an AJAX action, a...
CVE-2025-64983HIGH8.6Smart Video Doorbell firmware versions prior to 2.01.078 contain an active debug code vulnerability that allows an attac...
CVE-2025-66235Rejected reason: Not used
CVE-2025-66234Rejected reason: Not used
CVE-2025-66233Rejected reason: Not used
CVE-2025-66232Rejected reason: Not used
CVE-2025-66231Rejected reason: Not used
CVE-2025-66230Rejected reason: Not used
CVE-2025-66229Rejected reason: Not used
CVE-2025-66228Rejected reason: Not used
CVE-2025-66026MEDIUM6.1REDAXO is a PHP-based CMS. Prior to version 5.20.1, a reflected Cross-Site Scripting (XSS) vulnerability exists in the M...
CVE-2025-66025MEDIUM4.3Caido is a web security auditing toolkit. Prior to version 0.53.0, the Markdown renderer used in Caido’s Findings page i...
CVE-2025-66022CRITICAL9.8FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to version 1.7.1, an extension execution pa...
CVE-2025-66269HIGH7.1The RupsMon and USBMate services in UPSilon 2000 run with SYSTEM privileges and contain unquoted service paths. This all...
CVE-2025-66266CRITICAL9.3The RupsMon.exe service executable in UPSilon 2000 has insecure permissions, allowing the 'Everyone' group Full Control....
CVE-2025-66021MEDIUM6.1OWASP Java HTML Sanitizer is a configureable HTML Sanitizer written in Java, allowing inclusion of HTML authored by thir...
CVE-2025-66020HIGH7.5Valibot helps validate data using a schema. In versions from 0.31.0 to 1.1.0, the EMOJI_REGEX used in the emoji action i...
CVE-2025-12848MEDIUM6.1Webform Multiple File Upload module for Drupal 7.x contains a cross-site scripting (XSS) vulnerability in the file name ...
CVE-2025-66265MEDIUM6.9CMService.exe creates the C:\\usr directory and subdirectories with insecure permissions, granting write access to all a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now