2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-1815HIGH7.3A vulnerability, which was classified as critical, was found in pbrong hrms up to 1.0.1. This affects the function HrmsD...
CVE-2025-1812HIGH8.8A vulnerability classified as critical has been found in zj1983 zz up to 2024-08. Affected is the function GetUserOrg of...
CVE-2025-1811HIGH7.3A vulnerability was found in AT Software Solutions ATSVD up to 3.4.1. It has been declared as critical. Affected by this...
CVE-2025-1809HIGH7.3A vulnerability was found in Pixsoft Sol up to 7.6.6c and classified as critical. This issue affects some unknown proces...
CVE-2025-25724HIGH7.8list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a...
CVE-2025-1808HIGH7.3A vulnerability has been found in Pixsoft E-Saphira 1.7.24 and classified as critical. This vulnerability affects unknow...
CVE-2025-1804HIGH7.3A vulnerability was found in Blizzard Battle.Net up to 2.39.0.15212 on Windows and classified as critical. Affected by t...
CVE-2025-1800HIGH8.8A vulnerability has been found in D-Link DAR-7000 3.2 and classified as critical. This vulnerability affects the functio...
CVE-2025-1788HIGH7.8A vulnerability, which was classified as critical, was found in rizinorg rizin up to 0.8.0. This affects the function rz...
CVE-2025-1786HIGH7.8A vulnerability was found in rizinorg rizin up to 0.7.4. It has been rated as critical. This issue affects the function ...
CVE-2025-23119HIGH7.5An Improper Neutralization of Escape Sequences vulnerability could allow an Authentication Bypass with a Remote Code Exe...
CVE-2025-25723HIGH8.4Buffer Overflow vulnerability in GPAC version 2.5 allows a local attacker to execute arbitrary code.
CVE-2025-25635HIGH8TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improp...
CVE-2025-25610HIGH8TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improp...
CVE-2025-25609HIGH8TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improp...
CVE-2025-25428HIGH8TRENDnet TEW-929DRU 1.0.0.10 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows a...
CVE-2025-24849HIGH7.5Lack of encryption in transit for cloud infrastructure facilitating potential for sensitive data manipulation or exposur...
CVE-2025-20060HIGH8.7An attacker could expose cross-user personal identifiable information (PII) and personal health information transmitted ...
CVE-2025-20049HIGH7.1The Dario Health portal service application is vulnerable to XSS, which could allow an attacker to obtain sensitive info...
CVE-2025-26326HIGH8.8A vulnerability was identified in the NVDA Remote (version 2.6.4) and Tele NVDA Remote (version 2025.3.3) remote connect...
CVE-2025-22270HIGH7.3An attacker with access to the Administration panel, specifically the "Role Management" tab, can inject code by adding a...
CVE-2025-1319HIGH7.2The Site Mailer – SMTP Replacement, Email API Deliverability & Email Log plugin for WordPress is vulnerable to Stored Cr...
CVE-2025-1413HIGH8.4DaVinci Resolve on MacOS was found to be installed with incorrect file permissions (rwxrwxrwx). This is inconsistent wit...
CVE-2025-1572HIGH8.8The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the ‘u_i...
CVE-2025-0975HIGH8.8IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated user to execute code due to improper ne...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now