2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-60691HIGH8.8A stack-based buffer overflow exists in the httpd binary of Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar....
CVE-2025-60690HIGH8.8A stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (F...
CVE-2025-20355MEDIUM4.7A vulnerability in the web-based management interface of Cisco Catalyst Center Virtual Appliance could allow an unauthen...
CVE-2025-20353MEDIUM6.1A vulnerability in the web-based management interface of Cisco Catalyst Center could allow an unauthenticated, remote at...
CVE-2025-20349HIGH8.8A vulnerability in the REST API of Cisco Catalyst Center could allow an authenticated, remote attacker to execute arbitr...
CVE-2025-20346MEDIUM4.3A vulnerability in Cisco Catalyst Center could allow an authenticated, remote attacker to execute operations that should...
CVE-2025-20341HIGH8.8A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate priv...
CVE-2025-13121HIGH7.3A security vulnerability has been detected in cameasy Liketea 1.0.0. Impacted is the function list of the file laravel/a...
CVE-2025-11538MEDIUM6.8A vulnerability exists in Keycloak's server distribution where enabling debug mode (--debug <port>) insecurely defaults ...
CVE-2025-64718MEDIUM5.3js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to mod...
CVE-2025-64717CRITICAL9.8ZITADEL is an open source identity management platform. Starting in version 2.50.0 and prior to versions 2.71.19, 3.4.4,...
CVE-2025-64714MEDIUM5.8PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Starting in version 1.7.7 and prior...
CVE-2025-64703MEDIUM6.5MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can get sensitive informations b...
CVE-2025-64525MEDIUM6.5Astro is a web framework. In Astro versions 2.16.0 up to but excluding 5.15.5 which utilizeon-demand rendering, request ...
CVE-2025-64511HIGH8.8MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can access internal network serv...
CVE-2025-62484CRITICAL9.8Inefficient regular expression complexity in certain Zoom Workplace Clients before version 6.5.10 may allow an unauthent...
CVE-2025-60689MEDIUM5.4An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200...
CVE-2025-60688MEDIUM6.5A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681...
CVE-2025-60687MEDIUM6.5An unauthenticated command injection vulnerability exists in the ToToLink LR1200GB Router firmware V9.1.0u.6619_B2023013...
CVE-2025-60686MEDIUM5.1A local stack-based buffer overflow vulnerability exists in the infostat.cgi and cstecgi.cgi binaries of ToToLink router...
CVE-2025-60685MEDIUM5.1A stack buffer overflow exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary (s...
CVE-2025-60684MEDIUM6.5A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681...
CVE-2025-60683MEDIUM6.5A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf...
CVE-2025-60682MEDIUM6.5A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the cloudup...
CVE-2025-52186MEDIUM6.5Lichess lila before commit 11b4c0fb00f0ffd823246f839627005459c8f05c (2025-06-02) contains a Server-Side Request Forgery ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now