2025 CVE Vulnerabilities

45,173 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-5905HIGH8.8A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been rated as critical. Affected by this issue is the fun...
CVE-2025-5904HIGH8.8A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. Affected by this vulnerability...
CVE-2025-5903HIGH8.8A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been classified as critical. Affected is the function set...
CVE-2025-5902HIGH8.8A vulnerability was found in TOTOLINK T10 4.1.8cu.5207 and classified as critical. This issue affects the function setUp...
CVE-2025-5901HIGH8.8A vulnerability has been found in TOTOLINK T10 4.1.8cu.5207 and classified as critical. This vulnerability affects the f...
CVE-2025-30515HIGH8.8CyberData 011209 Intercom could allow an authenticated attacker to upload arbitrary files to multiple locations within...
CVE-2025-30507HIGH7.5CyberData 011209 Intercom could allow an unauthenticated user to gather sensitive information through blind SQL injectio...
CVE-2025-30183HIGH8.7CyberData 011209 Intercom does not properly store or protect web server admin credentials.
CVE-2025-26468HIGH8.7CyberData  011209 Intercom exposes features that could allow an unauthenticated to gain access and cause a denial-of...
CVE-2025-5900HIGH7.1A vulnerability, which was classified as problematic, was found in Tenda AC9 15.03.02.13. This affects an unknown part. ...
CVE-2025-49140HIGH7.5Pion Interceptor is a framework for building RTP/RTCP communication software. Versions v0.1.36 through v0.1.38 contain a...
CVE-2025-5897HIGH7.5A vulnerability was found in vuejs vue-cli up to 5.0.8. It has been rated as problematic. This issue affects the functio...
CVE-2025-5896HIGH7.5A vulnerability was found in tarojs taro up to 4.1.1. It has been declared as problematic. This vulnerability affects un...
CVE-2025-49141HIGH8.8HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.3, the `gitImportS...
CVE-2025-49004HIGH7.5Caido is a web security auditing toolkit. Prior to version 0.48.0, due to the lack of protection for DNS rebinding, Caid...
CVE-2025-5914HIGH7.8A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data...
CVE-2025-5895HIGH7.5A vulnerability was found in Metabase 54.10. It has been classified as problematic. This affects the function parseDataU...
CVE-2025-5892HIGH7.5A vulnerability, which was classified as problematic, has been found in RocketChat up to 7.6.1. This issue affects the f...
CVE-2025-49653HIGH8Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users o...
CVE-2025-49651HIGH8.1Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or al...
CVE-2025-45001HIGH7.5react-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remote) as encryption cipher and Base64 chun...
CVE-2025-49282HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-49281HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-49280HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-49279HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now