2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-2549HIGH8.8A vulnerability has been found in D-Link DIR-618 and DIR-605L 2.02/3.02 and classified as problematic. Affected by this ...
CVE-2025-2480HIGH8.4Santesoft Sante DICOM Viewer Pro is vulnerable to an out-of-bounds write, which requires a user to open a malicious DCM ...
CVE-2025-29149HIGH7.5Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the ping1 parameter in the formSetAutoPing fun...
CVE-2025-29121HIGH7.5A vulnerability was found in Tenda AC6 V15.03.05.16. The vulnerability affects the functionality of the /goform/fast_set...
CVE-2025-2548HIGH8.8A vulnerability, which was classified as problematic, was found in D-Link DIR-618 and DIR-605L 2.02/3.02. Affected is an...
CVE-2025-29214HIGH7.5Tenda AX12 v22.03.01.46_CN was discovered to contain a stack overflow via the sub_42F69C function at /goform/setMacFilte...
CVE-2025-23120HIGH8.8A vulnerability allowing remote code execution (RCE) for domain users.
CVE-2025-29101HIGH7.5Tenda AC8V4.0 V16.03.34.06 was discovered to contain a stack overflow via the deviceid parameter in the get_parentContro...
CVE-2025-2539HIGH7.5The File Away plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the...
CVE-2025-1796HIGH8.8A vulnerability in langgenius/dify v0.10.1 allows an attacker to take over any account, including administrator accounts...
CVE-2025-1473HIGH7.1A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20....
CVE-2025-1451HIGH7.5A vulnerability in parisneo/lollms-webui v13 arises from the server's handling of multipart boundaries in file uploads. ...
CVE-2025-1040HIGH8.8AutoGPT versions 0.3.4 and earlier are vulnerable to a Server-Side Template Injection (SSTI) that could lead to Remote C...
CVE-2025-0628HIGH8.1An improper authorization vulnerability exists in the main-latest version of BerriAI/litellm. When a user with the role ...
CVE-2025-0454HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability was identified in the Requests utility of significant-gravitas/autogp...
CVE-2025-0453HIGH7.5In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can cr...
CVE-2025-0452HIGH8.2eosphoros-ai/DB-GPT version latest is vulnerable to arbitrary file deletion on Windows systems via the '/v1/agent/hub/up...
CVE-2025-0330HIGH7.5In berriai/litellm version v1.52.1, an issue in proxy_server.py causes the leakage of Langfuse API keys when an error oc...
CVE-2025-0317HIGH7.5A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to upload and create a customized GGUF model ...
CVE-2025-0315HIGH7.5A vulnerability in ollama/ollama <=0.3.14 allows a malicious user to create a customized GGUF model file, upload it to t...
CVE-2025-0312HIGH7.5A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to create a customized GGUF model file that, ...
CVE-2025-0190HIGH7.5In version 3.25.0 of aimhubio/aim, a denial of service vulnerability exists. By tracking a large number of `Text` object...
CVE-2025-0189HIGH7.5In version 3.25.0 of aimhubio/aim, the tracking server is vulnerable to a denial of service attack. The server overrides...
CVE-2025-0187HIGH7.5A Denial of Service (DoS) vulnerability was discovered in the file upload feature of gradio-app/gradio version 0.39.1. T...
CVE-2025-0185HIGH8.8A vulnerability in the Dify Tools' Vanna module of the langgenius/dify repository allows for a Pandas Query Injection in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now