2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-1433HIGH7.8A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A...
CVE-2025-1432HIGH7.8A maliciously crafted 3DM file, when parsed through Autodesk AutoCAD, can force a Use-After-Free vulnerability. A malici...
CVE-2025-1431HIGH7.8A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. ...
CVE-2025-1430HIGH7.8A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force a Memory Corruption vulnerability. A ...
CVE-2025-1429HIGH7.8A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A...
CVE-2025-1428HIGH7.8A maliciously crafted CATPART file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability....
CVE-2025-1427HIGH7.8A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnera...
CVE-2025-29363HIGH7.5Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to buffer overflow via the schedStartTime and schedEndTime...
CVE-2025-29362HIGH7.5Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the list parameter at /goform/setPp...
CVE-2025-29361HIGH7.5Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the list parameter at /goform/SetVi...
CVE-2025-29360HIGH7.5Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the time and timeZone parameters at...
CVE-2025-29359HIGH7.5Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the deviceId parameter at /goform/s...
CVE-2025-29358HIGH7.5Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the firewallEn parameter at /goform...
CVE-2025-29357HIGH7.5Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the startIp and endIp parameters at...
CVE-2025-2280HIGH8.1Improper access control in web extension restriction feature in Devolutions Server 2024.3.4.0 and earlier allows an au...
CVE-2025-2277HIGH7.5Exposure of password in web-based SSH authentication component in Devolutions Server 2024.3.13 and earlier allows a user...
CVE-2025-29998HIGH8.2This vulnerability exists in the CAP back office application due to missing rate limiting on OTP requests in an API endp...
CVE-2025-29997HIGH8.2This vulnerability exists in the CAP back office application due to improper authorization checks on certain API endpoin...
CVE-2025-29996HIGH8.2This vulnerability exists in the CAP back office application due to improper implementation of OTP verification mechanis...
CVE-2025-29995HIGH8.3This vulnerability exists in the CAP back office application due to a weak password-reset mechanism implemented at API e...
CVE-2025-29994HIGH8.2This vulnerability exists in the CAP back office application due to improper authentication check at the API endpoint. A...
CVE-2025-25175HIGH7.8A vulnerability has been identified in Simcenter Femap V2401 (All versions < V2401.0003), Simcenter Femap V2406 (All ver...
CVE-2025-1785HIGH8.1The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3...
CVE-2025-2271HIGH7.7A vulnerability exists in Issuetrak v17.2.2 and prior that allows a low-privileged user to access audit results of other...
CVE-2025-1119HIGH7.3The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to arb...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now