2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-4756HIGH7.5A vulnerability was found in D-Link DI-7003GV2 24.04.18D1 R(68125). It has been declared as problematic. This vulnerabil...
CVE-2025-4751HIGH7.5A vulnerability, which was classified as problematic, was found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected is an...
CVE-2025-4749HIGH8.7A vulnerability classified as critical was found in D-Link DI-7003GV2 24.04.18D1 R(68125). This vulnerability affects th...
CVE-2025-4743HIGH8.8A vulnerability classified as critical was found in code-projects Employee Record System 1.0. Affected by this vulnerabi...
CVE-2025-4735HIGH8.8A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this ...
CVE-2025-4733HIGH8.8A vulnerability, which was classified as critical, has been found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. T...
CVE-2025-4732HIGH8.8A vulnerability classified as critical was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. This vulnerability...
CVE-2025-47809HIGH8.2Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reb...
CVE-2025-4731HIGH8.8A vulnerability classified as critical has been found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. This affects ...
CVE-2025-4730HIGH8.8A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been rated as critical. Affected b...
CVE-2025-47287HIGH7.5Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser enc...
CVE-2025-47785HIGH8.8Emlog is an open source website building system. In versions up to and including 2.5.9, SQL injection occurs because the...
CVE-2025-47161HIGH7.8Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
CVE-2025-32922HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads allows Stored XSS.This iss...
CVE-2025-30476HIGH7.5Dell PowerScale InsightIQ, version 5.2, contains an uncontrolled resource consumption vulnerability. An unauthenticated ...
CVE-2025-26481HIGH7.5Dell PowerScale OneFS, versions 9.4.0.0 through 9.9.0.0, contains an uncontrolled resource consumption vulnerability. A ...
CVE-2025-30421HIGH7.8There is a memory corruption vulnerability due to a stack-based buffer overflow in DrObjectStorage::XML_Serialize() when...
CVE-2025-30420HIGH7.8There is a memory corruption vulnerability due to an out of bounds read in Bitmap::InternalDraw() when using the SymbolE...
CVE-2025-30419HIGH7.8There is a memory corruption vulnerability due to an out of bounds read in GetSymbolBorderRectSize() when using the Symb...
CVE-2025-30418HIGH7.8There is a memory corruption vulnerability due to an out of bounds write in CheckPins() when using the SymbolEditor in N...
CVE-2025-30417HIGH7.8There is a memory corruption vulnerability due to an out of bounds write in Library!DecodeBase64() when using the Symbol...
CVE-2025-4704HIGH7.3A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected by t...
CVE-2025-48050HIGH7.5In DOMPurify through 3.2.5 before 6bc6d60, scripts/server.js does not ensure that a pathname is located under the curren...
CVE-2025-4696HIGH8.8A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been declared as critical. Af...
CVE-2025-4695HIGH8.8A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been classified as critical. ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now