2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-50647 | HIGH | 7.5 | 0.5% | Apr 8, 2026 | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1, specifically in the handling of the wans parameter ... |
| CVE-2025-50646 | HIGH | 7.5 | 0.5% | Apr 8, 2026 | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to insufficient input validation on the name par... |
| CVE-2025-50645 | HIGH | 7.5 | 0.5% | Apr 8, 2026 | A vulnerability has been discovered in D-Link DI-8003 16.07.26A1, which can lead to a buffer overflow when the s paramet... |
| CVE-2025-50644 | HIGH | 7.5 | 0.5% | Apr 8, 2026 | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper validation of user input in the qj.a... |
| CVE-2025-30650 | HIGH | 8.4 | 0.1% | Apr 8, 2026 | A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a... |
| CVE-2025-52222 | HIGH | 7.5 | 0.3% | Apr 8, 2026 | D-Link DI-8003 v16.07.26A1, DI-8500 v16.07.26A1; DI-8003G v17.12.21A1, DI-8200G v17.12.20A1, DI-8200 v16.07.26A1, DI-840... |
| CVE-2025-52221 | CRITICAL | 9.8 | 0.4% | Apr 8, 2026 | Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function via the funcname, funcpara1, and... |
| CVE-2025-45059 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | D-Link DI-8300 v16.07.26A1 was discovered to contain a buffer overflow via the fn parameter in the tgfile_htm function. ... |
| CVE-2025-45058 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | D-Link DI-8300 v16.07.26A1 was discovered to contain a buffer overflow via the fx parameter in the jingx_asp function. T... |
| CVE-2025-45057 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | D-Link DI-8300 v16.07.26A1 was discovered to contain a buffer overflow via the ip parameter in the ip_position_asp funct... |
| CVE-2025-57175 | MEDIUM | 6.8 | 0.1% | Apr 8, 2026 | Siklu EtherHaul 8010 siklu-uimage-nxp-enc-10_6_2-18707-ea552dc00b devices have a static root password. |
| CVE-2025-14243 | MEDIUM | 5.3 | 0.3% | Apr 8, 2026 | A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enum... |
| CVE-2025-58713 | MEDIUM | 6.4 | 0.1% | Apr 8, 2026 | A container privilege escalation flaw was found in certain Red Hat Process Automation Manager images. This issue stems f... |
| CVE-2025-57854 | MEDIUM | 6.4 | 0.1% | Apr 8, 2026 | A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from... |
| CVE-2025-57853 | MEDIUM | 6.4 | 0.2% | Apr 8, 2026 | A container privilege escalation flaw was found in certain Web Terminal images. This issue stems from the /etc/passwd fi... |
| CVE-2025-57851 | MEDIUM | 6.7 | 0.1% | Apr 8, 2026 | A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems f... |
| CVE-2025-57847 | MEDIUM | 6.4 | 0.2% | Apr 8, 2026 | A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from th... |
| CVE-2025-14816 | CRITICAL | 9.3 | 0.1% | Apr 8, 2026 | Cleartext Storage of Sensitive Information in GUI vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and pr... |
| CVE-2025-14815 | CRITICAL | 9.3 | 0.1% | Apr 8, 2026 | Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mi... |
| CVE-2025-1794 | MEDIUM | 5.4 | 0.2% | Apr 8, 2026 | The AM LottiePlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded SVG files in all vers... |
| CVE-2025-14732 | MEDIUM | 6.4 | 0.3% | Apr 8, 2026 | The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2025-20628 | MEDIUM | 6.9 | 0.2% | Apr 7, 2026 | An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) w... |
| CVE-2025-69515 | CRITICAL | 9.1 | 0.5% | Apr 7, 2026 | An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system int... |
| CVE-2025-56015 | HIGH | 7.5 | 0.4% | Apr 7, 2026 | In GenieACS 1.2.13, an unauthenticated access vulnerability exists in the NBI API endpoint. |
| CVE-2025-14859 | HIGH | 7 | 0.1% | Apr 7, 2026 | The Semtech LR11xx LoRa transceivers implement secure boot functionality using digital signatures to authenticate firmwa... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now