2025 CVE Vulnerabilities

45,207 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-60938HIGH7.5Emoncms 11.7.3 has a remote code execution vulnerability in the firmware upload feature that allows authenticated users ...
CVE-2025-60936MEDIUM6.1Emoncms 11.7.3 is vulnerable to Cross Site in the input handling mechanism. This vulnerability allows authenticated atta...
CVE-2025-60572HIGH7.5D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formA...
CVE-2025-60571HIGH7.5D-Link DIR600LAx FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSe...
CVE-2025-60570HIGH7.5D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formL...
CVE-2025-60569HIGH7.5D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formS...
CVE-2025-60568HIGH7.5D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formA...
CVE-2025-56438MEDIUM6.8An issue in the firmware update mechanism of Nous W3 Smart WiFi Camera v1.33.50.82 allows unauthenticated and physically...
CVE-2025-43995CRITICAL9.8Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An ...
CVE-2025-43994HIGH7.5Dell Storage Center - Dell Storage Manager, version(s) DSM 20.1.21, contain(s) a Missing Authentication for Critical Fun...
CVE-2025-11145HIGH7.5Observable Discrepancy, Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Private Personal Informa...
CVE-2025-46425MEDIUM6.5Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entit...
CVE-2025-46185MEDIUM6.2An Insecure Permission vulnerability in pgcodekeeper 10.12.0 allows a local attacker to obtain sensitive information via...
CVE-2025-46183HIGH8.2The Utils.deserialize function in pgCodeKeeper 10.12.0 processes serialized data from untrusted sources. If an attacker ...
CVE-2025-40024HIGH7.8In the Linux kernel, the following vulnerability has been resolved: vhost: Take a reference on the task in struct vhost...
CVE-2025-40023In the Linux kernel, the following vulnerability has been resolved: drm/xe/vf: Don't expose sysfs attributes not applic...
CVE-2025-40022In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Fix incorrect boolean values in af...
CVE-2025-40021In the Linux kernel, the following vulnerability has been resolved: tracing: dynevent: Add a missing lockdown check on ...
CVE-2025-40020In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: fix shift-out-of-bounds issue Expli...
CVE-2025-11576MEDIUM4.3The AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant plugin for WordPress is vulnerable to CSV In...
CVE-2025-40019In the Linux kernel, the following vulnerability has been resolved: crypto: essiv - Check ssize for decryption and in-p...
CVE-2025-40018HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ipvs: Defer ip_vs_ftp unregister during netns clean...
CVE-2025-10861HIGH7.5The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPr...
CVE-2025-5605MEDIUM5.3An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor wit...
CVE-2025-5350MEDIUM4.8SSRF and Reflected XSS Vulnerabilities exist in multiple WSO2 products within the deprecated Try-It feature, which was a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now