2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-60858HIGH7.5Reolink Video Doorbell Wi-Fi DB_566128M5MP_W stores and transmits DDNS credentials in plaintext within its configuration...
CVE-2025-60349HIGH7.5An issue was discovered in Prevx v3.0.5.220 allowing attackers to cause a denial of service via sending IOCTL code 0x22E...
CVE-2025-56399HIGH8.8alexusmai laravel-file-manager 3.3.1 and before allows an authenticated attacker to achieve Remote Code Execution (RCE) ...
CVE-2025-36386CRITICAL9.8IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authen...
CVE-2025-34294Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the behavior originates fr...
CVE-2025-61128CRITICAL9.1Stack-based buffer overflow vulnerability in WAVLINK QUANTUM D3G/WL-WN530HG3 firmware M30HG3_V240730, and possibly other...
CVE-2025-61107HIGH7.5FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_p...
CVE-2025-61106HIGH7.5FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_p...
CVE-2025-61104HIGH7.5FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_unknown_tl...
CVE-2025-61103HIGH7.5FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_l...
CVE-2025-61043CRITICAL9.1An out-of-bounds read vulnerability has been discovered in Monkey's Audio 11.31, specifically in the CAPECharacterHelper...
CVE-2025-36085MEDIUM5.4IBM Concert 1.0.0 through 2.0.0 Software is vulnerable to server-side request forgery (SSRF). This may allow an authenti...
CVE-2025-36083MEDIUM5.5IBM Concert Software 1.0.0 through 2.0.0 could allow a local user to obtain sensitive information from buffers due to ...
CVE-2025-36081MEDIUM5.3IBM Concert Software 1.0.0 through 2.0.0 could allow a user to modify system logs due to improper neutralization of log...
CVE-2025-34318MEDIUM5.1IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an...
CVE-2025-34317MEDIUM5.4IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an...
CVE-2025-34316MEDIUM5.4IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an...
CVE-2025-34315MEDIUM5.4IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an...
CVE-2025-34314MEDIUM5.4IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an...
CVE-2025-34313MEDIUM5.4IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an...
CVE-2025-34312HIGH8.8IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated a...
CVE-2025-34311HIGH8.8IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated a...
CVE-2025-34310MEDIUM5.4IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an...
CVE-2025-34309MEDIUM5.4IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an...
CVE-2025-34308MEDIUM5.4IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now