2025 CVE Vulnerabilities

45,177 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-35004HIGH7.1Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command in...
CVE-2025-32459HIGH7.8The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the sync_time argument), that is vu...
CVE-2025-32458HIGH7.8The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the get_syslog_from_qtn argument), ...
CVE-2025-32457HIGH7.8The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the get_file_from_qtn argument), th...
CVE-2025-32456HIGH7.8The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the put_file_to_qtn argument), that...
CVE-2025-32455HIGH7.8The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the run_cmd argument), that is vuln...
CVE-2025-5847HIGH8.8A vulnerability has been found in Tenda AC9 15.03.02.13 and classified as critical. Affected by this vulnerability is th...
CVE-2025-38004HIGH7.1In the Linux kernel, the following vulnerability has been resolved: can: bcm: add locking for bcm_op runtime updates T...
CVE-2025-5840HIGH7.3A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. Th...
CVE-2025-5839HIGH8.8A vulnerability, which was classified as critical, has been found in Tenda AC9 15.03.02.13. Affected by this issue is th...
CVE-2025-5838HIGH8.8A vulnerability classified as critical was found in PHPGurukul Employee Record Management System 1.3. Affected by this v...
CVE-2025-5837HIGH8.8A vulnerability classified as critical has been found in PHPGurukul Employee Record Management System 1.3. Affected is a...
CVE-2025-49619HIGH8.5Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks suc...
CVE-2025-5303HIGH7.2The LTL Freight Quotes – Freightview Edition, LTL Freight Quotes – Daylight Edition and LTL Freight Quotes – Day & Ross ...
CVE-2025-5399HIGH7.5Due to a mistake in libcurl's WebSocket code, a malicious server can send a particularly crafted packet which makes libc...
CVE-2025-47601HIGH8.8Missing Authorization vulnerability in Christiaan Pieterse MaxiBlocks maxi-blocks allows Privilege Escalation.This issue...
CVE-2025-49127HIGH8.9Kafbat UI is a web user interface for managing Apache Kafka clusters. An unsafe deserialization vulnerability in version...
CVE-2025-5799HIGH8.8A vulnerability was found in Tenda AC8 16.03.34.09. It has been declared as critical. Affected by this vulnerability is ...
CVE-2025-5798HIGH8.8A vulnerability was found in Tenda AC8 16.03.34.09. It has been classified as critical. Affected is the function fromSet...
CVE-2025-5795HIGH8.8A vulnerability, which was classified as critical, was found in Tenda AC5 1.0/15.03.06.47. This affects the function fro...
CVE-2025-5794HIGH8.8A vulnerability, which was classified as critical, has been found in Tenda AC5 15.03.06.47. Affected by this issue is th...
CVE-2025-5481HIGH7.8Sante DICOM Viewer Pro DCM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allo...
CVE-2025-5480HIGH7.8Action1 Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attac...
CVE-2025-5474HIGH7.32BrightSparks SyncBackFree Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local atta...
CVE-2025-5473HIGH8.8GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now