2025 CVE Vulnerabilities

45,202 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-65222MEDIUM4.3Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the rebootTime parameter of /goform/SetSysAutoRebbotCfg.
CVE-2025-65221MEDIUM4.3Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the list parameter of /goform/setPptpUserList.
CVE-2025-65220MEDIUM4.3Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow in: /goform/SetVirtualServerCfg via the list parameter.
CVE-2025-64984MEDIUM6.1Kaspersky has fixed a security issue in Kaspersky Endpoint Security for Linux (any version with anti-virus databases pri...
CVE-2025-62346MEDIUM6.8A Cross-Site Request Forgery (CSRF) vulnerability was identified in HCL Glovius Cloud. An attacker can force a user's we...
CVE-2025-60799MEDIUM6.1phpPgAdmin 7.13.0 and earlier contains an incorrect access control vulnerability in sql.php at lines 68-76. The applicat...
CVE-2025-60798MEDIUM6.5phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in display.php at line 396. The application passes ...
CVE-2025-60797MEDIUM6.5phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in dataexport.php at line 118. The application dire...
CVE-2025-60796MEDIUM6.1phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting (XSS) vulnerabilities across various components. Us...
CVE-2025-60794MEDIUM6.5Session tokens and passwords in couch-auth 0.21.2 are stored in JavaScript objects and remain in memory without explicit...
CVE-2025-5092MEDIUM6.4Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled ligh...
CVE-2025-41076MEDIUM6.5In version 6.13.0 of LimeSurvey, any external user can cause a 500 error in the survey system by sending a malformed ses...
CVE-2025-41075HIGH7.5Vulnerability in LimeSurvey 6.13.0 in the endpoint /optin that causes infinite HTTP redirects when accessed directly. Th...
CVE-2025-41074HIGH7.5Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. ...
CVE-2025-40605MEDIUM5.3A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file...
CVE-2025-40604CRITICAL9.8Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem i...
CVE-2025-40601HIGH7.5A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to ca...
CVE-2025-13469MEDIUM4.8A security vulnerability has been detected in Public Knowledge Project omp and ojs 3.3.0/3.4.0/3.5.0. Impacted is an unk...
CVE-2025-13468HIGH8.1A weakness has been identified in SourceCodester Alumni Management System 1.0. This issue affects the function delete_fo...
CVE-2025-13451CRITICAL9.8A vulnerability was identified in SourceCodester Online Shop Project 1.0. The affected element is an unknown function of...
CVE-2025-13450MEDIUM5.4A vulnerability was determined in SourceCodester Online Shop Project 1.0. Impacted is an unknown function of the file /s...
CVE-2025-13449CRITICAL9.8A vulnerability was found in code-projects Online Shop Project 1.0. This issue affects some unknown processing of the fi...
CVE-2025-13446CRITICAL9.8A vulnerability has been found in Tenda AC21 16.03.08.16. This vulnerability affects unknown code of the file /goform/Se...
CVE-2025-13445CRITICAL9.8A flaw has been found in Tenda AC21 16.03.08.16. This affects an unknown part of the file /goform/SetIpMacBind. Executin...
CVE-2025-13443MEDIUM6.5A vulnerability was detected in macrozheng mall up to 1.0.3. Affected by this issue is the function delete of the file /...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now