2025 CVE Vulnerabilities

45,209 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-22175MEDIUM5.4Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a...
CVE-2025-22174MEDIUM4.3Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a...
CVE-2025-22173MEDIUM4.3Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a...
CVE-2025-22172MEDIUM4.3Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a...
CVE-2025-22171MEDIUM4.3Jira Align is vulnerable to an authorization issue. A low-privilege user is able to alter the private checklists of othe...
CVE-2025-22170MEDIUM4.3Jira Align is vulnerable to an authorization issue. A low-privilege user without sufficient privileges to perform an act...
CVE-2025-22169MEDIUM5.4Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a...
CVE-2025-22168MEDIUM4.3Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a...
CVE-2025-11958MEDIUM5.1An improper input validation in the Security Dashboard ignored-tasks API of Devolutions Server 2025.2.15.0 and earlier a...
CVE-2025-11957CRITICAL9Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenti...
CVE-2025-8677HIGH7.5Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaust...
CVE-2025-62659LOW2.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-62607MEDIUM5.3Nautobot Single Source of Truth (SSoT) is an app for Nautobot. Prior to version 3.10.0, an unauthenticated attacker coul...
CVE-2025-60338HIGH7.5Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the DhcpListClient functi...
CVE-2025-60335HIGH7.5A NULL pointer dereference in the main function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a De...
CVE-2025-60334HIGH7.5TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the ssid parameter in the setWiFiBa...
CVE-2025-60333HIGH7.5TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the wepkey2 parameter in the setWiF...
CVE-2025-40780HIGH8.6In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible f...
CVE-2025-40778HIGH8.6Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject for...
CVE-2025-23299MEDIUM6.7NVIDIA Bluefield and ConnectX contain a vulnerability in the management interface that could allow a malicious actor wit...
CVE-2025-62606HIGH8.8my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to ...
CVE-2025-62604HIGH7.5MeterSphere is an open source continuous testing platform. Prior to version 2.10.25-lts, a logic flaw allows retrieval o...
CVE-2025-62526HIGH7.8OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, ubusd contains a heap ...
CVE-2025-62525HIGH8.8OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, local users could read...
CVE-2025-62073MEDIUM4.3Missing Authorization vulnerability in Sovlix MeetingHub meetinghub.This issue affects MeetingHub: from n/a through <= 1...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now