2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-62267MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in web content template’s select structure page in Liferay Portal 7....
CVE-2025-12547HIGH8.1A vulnerability was identified in LogicalDOC Community Edition up to 9.2.1. This vulnerability affects unknown code of t...
CVE-2025-12546MEDIUM5.4A vulnerability was determined in LogicalDOC Community Edition up to 9.2.1. This affects an unknown part of the componen...
CVE-2025-63459HIGH7.5Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_42...
CVE-2025-62264MEDIUM6.1Reflected cross-site scripting (XSS) vulnerability in Languauge Override in Liferay Portal 7.4.3.8 through 7.4.3.111, an...
CVE-2025-6075MEDIUM5.5If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding env...
CVE-2025-63465HIGH7.5Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_42288...
CVE-2025-63464HIGH7.5Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_42396...
CVE-2025-63463HIGH7.5Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the wifiOff parameter in the sub_42...
CVE-2025-63462HIGH7.5Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the wifiOff parameter in the sub_4...
CVE-2025-63461HIGH7.5Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the urldec...
CVE-2025-63460HIGH7.5Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_42...
CVE-2025-59501MEDIUM4.8Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing o...
CVE-2025-63469HIGH7.5Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_421BA...
CVE-2025-63468HIGH7.5Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the sub_...
CVE-2025-63467HIGH7.5Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_42540...
CVE-2025-63466HIGH7.5Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the sub_4...
CVE-2025-29270CRITICAL10Incorrect access control in the realtime.cgi endpoint of Deep Sea Electronics devices DSE855 v1.1.0 to v1.1.26 allows at...
CVE-2025-12554CRITICAL9.8Missing Security Headers.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
CVE-2025-12553CRITICAL9.8Email Server Certificate Verification Disabled.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
CVE-2025-12552CRITICAL9.8Insufficient Password Policy.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
CVE-2025-12509HIGH8.4On a client with an admin user, a Global_Shipping script can be implemented. The script could later be executed on the B...
CVE-2025-12508HIGH8.4When using domain users as BRAIN2 users, communication with Active Directory services is unencrypted. This can lead to t...
CVE-2025-12507HIGH8.8The service Bizerba Communication Server (BCS) has an unquoted service path. Due to the way Windows searches the executa...
CVE-2025-12357MEDIUM6.3By manipulating the Signal Level Attenuation Characterization (SLAC) protocol with spoofed measurements, an attacker ca...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now