2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-34241MEDIUM6.5Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxDeviceController.ajaxDevice...
CVE-2025-34240MEDIUM6.5Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AppManagementController.appUpgr...
CVE-2025-34239HIGH7.2Advantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppManagementController.app...
CVE-2025-34238MEDIUM6.5Advantech WebAccess/VPN versions prior to 1.1.5 contain an absolute path traversal via AjaxStandaloneVpnClientsControlle...
CVE-2025-34237MEDIUM5.4Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via Standalone...
CVE-2025-34236MEDIUM5.4Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via NetworksCo...
CVE-2025-12490HIGH8.8Netgate pfSense CE Suricata Path Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attacke...
CVE-2025-63551HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability, achievable through an XML External Entity (XXE) injection, exists in...
CVE-2025-60541HIGH7.3A Server-Side Request Forgery (SSRF) in the /api/proxy/ component of linshenkx prompt-optimizer v1.3.0 to v1.4.2 allows ...
CVE-2025-31133HIGH7.8runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, ...
CVE-2025-22397MEDIUM4.9Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions 6.10.80.00 thro...
CVE-2025-27919HIGH8.2An issue was discovered in AnyDesk through 9.0.4. A remotely connected user with the "Control my device" permission can ...
CVE-2025-27918CRITICAL9.8An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7....
CVE-2025-27917HIGH7.5An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7....
CVE-2025-27916HIGH7.5An issue was discovered in AnyDesk for Windows before 9.0.6 and AnyDesk for Android before 8.0.0. When the connection be...
CVE-2025-12815MEDIUM5.3An ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS ...
CVE-2025-63589HIGH7.1A reflected XSS vulnerability exists in CMSimple_XH 1.8's index.php router when attacker-controlled path segments are no...
CVE-2025-63588HIGH7.1An unauthenticated reflected cross-site scripting vulnerability in the query handling of CMSimpleXH allows remote attack...
CVE-2025-63560HIGH7.5An issue in KiloView Dual Channel 4k HDMI & 3G-SDI HEVC Video Encoder Firmware v.1.20.0006 allows a remote attacker to c...
CVE-2025-59396Rejected reason: Not a security vulnerability
CVE-2025-12808MEDIUM6.5Improper access control in Devolutions allows a View-only user to retrieve sensitive third-level nested fields, such as ...
CVE-2025-12485HIGH8.8Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated...
CVE-2025-10885HIGH7.8A maliciously crafted file, when executed on the victim's machine, can lead to privilege escalation to NT AUTHORITY/SYST...
CVE-2025-6327CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in KingAddons.com King Addons for Elementor king-addons al...
CVE-2025-6325CRITICAL9.8Incorrect Privilege Assignment vulnerability in KingAddons.com King Addons for Elementor king-addons allows Privilege Es...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now