2025 CVE Vulnerabilities

45,200 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-2761HIGH7.8GIMP FLI File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attacker...
CVE-2025-2760HIGH7.8GIMP XWD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers t...
CVE-2025-28028HIGH7.3TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2c...
CVE-2025-28025HIGH7.3TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2c...
CVE-2025-28022HIGH7.3TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in downloadFile.cgi through ...
CVE-2025-28021HIGH7.3TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the downloadFile.cgi thro...
CVE-2025-28020HIGH7.3TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through ...
CVE-2025-28019HIGH7.3TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi comp...
CVE-2025-28018HIGH7.3TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through ...
CVE-2025-1520HIGH8PostHog ClickHouse Table Functions SQL Injection Remote Code Execution Vulnerability. This vulnerability allows network-...
CVE-2025-1050HIGH8.8Sonos Era 300 Out-of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attack...
CVE-2025-1049HIGH8.8Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent...
CVE-2025-1048HIGH8.8Sonos Era 300 Speaker libsmb2 Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adja...
CVE-2025-1047HIGH7.8Luxion KeyShot PVS File Parsing Access of Uninitialized Pointer Remote Code Execution Vulnerability. This vulnerability ...
CVE-2025-1046HIGH7.8Luxion KeyShot SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote att...
CVE-2025-1045HIGH7.8Luxion KeyShot Viewer KSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabilit...
CVE-2025-32968HIGH8.8XWiki is a generic wiki platform. In versions starting from 1.6-milestone-1 to before 15.10.16, 16.4.6, and 16.10.1, it ...
CVE-2025-21605HIGH7.5Redis is an open source, in-memory database that persists on disk. In versions starting at 2.6 and prior to 7.4.3, An un...
CVE-2025-43965HIGH7.5In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used.
CVE-2025-42603HIGH8.7This vulnerability exists in the Meon KYC solutions due to transmission of sensitive data in plain text within the respo...
CVE-2025-42602HIGH8.2This vulnerability exists in Meon KYC solutions due to improper handling of access and refresh tokens in certain API end...
CVE-2025-42601HIGH8.2This vulnerability exists in Meon KYC solutions due to insufficient server-side validation of the Captcha in certain API...
CVE-2025-42600HIGH8.2This vulnerability exists in Meon KYC solutions due to missing restrictions on the number of incorrect One-Time Password...
CVE-2025-3530HIGH7.5The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to product price manipulation in all versions up t...
CVE-2025-3529HIGH8.2The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now