2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-59482HIGH8Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a...
CVE-2025-58455HIGH8Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a...
CVE-2025-58077HIGH8Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a...
CVE-2025-52631HIGH8.1HCL AION is affected by a Missing or Insecure HTTP Strict-Transport-Security (HSTS) Header vulnerability. This can allow...
CVE-2025-52628HIGH8.8HCL AION is affected by a Cookie with Insecure, Improper, or Missing SameSite vulnerability. This can allow cookies to ...
CVE-2025-70841HIGH7.5Dokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated remote attackers to obtain sensitive app...
CVE-2025-70758HIGH7.5chetans9 core-php-admin-panel through commit a94a780d6 contains an authentication bypass vulnerability in includes/auth_...
CVE-2025-70560HIGH8.4Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application us...
CVE-2025-69875HIGH7.8A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient val...
CVE-2025-66374HIGH7.8CyberArk Endpoint Privilege Manager Agent through 25.10.0 allows a local user to achieve privilege escalation through po...
CVE-2025-62599HIGH7.5eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management ...
CVE-2025-60865HIGH7.8Insecure Permissions vulnerability in avanquest Driver Updater v.9.1.57803.1174 allows a local attacker to escalate priv...
CVE-2025-59439HIGH7.5An issue was discovered in Samsung Mobile Processor, Wearable Processor and Modem Exynos 980, 990, 850, 1080, 9110, W920...
CVE-2025-52627HIGH7.5Root File System Not Mounted as Read-Only configuration vulnerability. This can allow unintended modifications to critic...
CVE-2025-14550HIGH7.5An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `ASGIRequest` allows a remote att...
CVE-2025-7760HIGH7.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ofisimo Web...
CVE-2025-6397HIGH8.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ankara Host...
CVE-2025-67853HIGH7.5A flaw was found in Moodle. A remote attacker could exploit a lack of proper rate limiting in the confirmation email ser...
CVE-2025-67851HIGH7.8A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper esc...
CVE-2025-67848HIGH8.1A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the ...
CVE-2025-59902HIGH7.1HTML injection vulnerability in NICE Chat. This vulnerability allows an attacker to inject and render arbitrary HTML con...
CVE-2025-8461HIGH7.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Seres Softw...
CVE-2025-8456HIGH7.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kod8 Softwa...
CVE-2025-8590HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in AKCE Software Technology R&D Industry and Tr...
CVE-2025-8589HIGH7.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AKCE Softwa...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now