2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-50647HIGH7.5A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1, specifically in the handling of the wans parameter ...
CVE-2025-50646HIGH7.5A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to insufficient input validation on the name par...
CVE-2025-50645HIGH7.5A vulnerability has been discovered in D-Link DI-8003 16.07.26A1, which can lead to a buffer overflow when the s paramet...
CVE-2025-50644HIGH7.5A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper validation of user input in the qj.a...
CVE-2025-30650HIGH8.4A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a...
CVE-2025-52222HIGH7.5D-Link DI-8003 v16.07.26A1, DI-8500 v16.07.26A1; DI-8003G v17.12.21A1, DI-8200G v17.12.20A1, DI-8200 v16.07.26A1, DI-840...
CVE-2025-52221CRITICAL9.8Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function via the funcname, funcpara1, and...
CVE-2025-45059HIGH7.5D-Link DI-8300 v16.07.26A1 was discovered to contain a buffer overflow via the fn parameter in the tgfile_htm function. ...
CVE-2025-45058HIGH7.5D-Link DI-8300 v16.07.26A1 was discovered to contain a buffer overflow via the fx parameter in the jingx_asp function. T...
CVE-2025-45057HIGH7.5D-Link DI-8300 v16.07.26A1 was discovered to contain a buffer overflow via the ip parameter in the ip_position_asp funct...
CVE-2025-57175MEDIUM6.8Siklu EtherHaul 8010 siklu-uimage-nxp-enc-10_6_2-18707-ea552dc00b devices have a static root password.
CVE-2025-14243MEDIUM5.3A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enum...
CVE-2025-58713MEDIUM6.4A container privilege escalation flaw was found in certain Red Hat Process Automation Manager images. This issue stems f...
CVE-2025-57854MEDIUM6.4A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from...
CVE-2025-57853MEDIUM6.4A container privilege escalation flaw was found in certain Web Terminal images. This issue stems from the /etc/passwd fi...
CVE-2025-57851MEDIUM6.7A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems f...
CVE-2025-57847MEDIUM6.4A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from th...
CVE-2025-14816CRITICAL9.3Cleartext Storage of Sensitive Information in GUI vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and pr...
CVE-2025-14815CRITICAL9.3Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mi...
CVE-2025-1794MEDIUM5.4The AM LottiePlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded SVG files in all vers...
CVE-2025-14732MEDIUM6.4The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2025-20628MEDIUM6.9An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) w...
CVE-2025-69515CRITICAL9.1An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system int...
CVE-2025-56015HIGH7.5In GenieACS 1.2.13, an unauthenticated access vulnerability exists in the NBI API endpoint.
CVE-2025-14859HIGH7The Semtech LR11xx LoRa transceivers implement secure boot functionality using digital signatures to authenticate firmwa...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now