2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-4186MEDIUM6.3A vulnerability, which was classified as critical, was found in Wangshen SecGate 3600 2024. Affected is an unknown funct...
CVE-2025-4185MEDIUM6.3A vulnerability, which was classified as critical, has been found in Wangshen SecGate 3600 2024. This issue affects some...
CVE-2025-4178MEDIUM5.4A vulnerability was found in xiaowei1118 java_server up to 11a5bac8f4ba1c17e4bc1b27cad6d24868500e3a on Windows and class...
CVE-2025-27365MEDIUM6.5IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, ...
CVE-2025-1333MEDIUM6.5IBM MQ Container when used with the IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through...
CVE-2025-4175MEDIUM6.3A vulnerability, which was classified as critical, was found in AlanBinu007 Spring-Boot-Advanced-Projects up to 3.1.3. T...
CVE-2025-46632MEDIUM6.5Initialization vector (IV) reuse in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an attacker to ...
CVE-2025-46631MEDIUM6.5Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote ...
CVE-2025-46630MEDIUM6.5Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote ...
CVE-2025-46629MEDIUM6.5Lack of access controls in the 'ate' management binary of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote...
CVE-2025-3517MEDIUM6.3Incorrect privilege assignment in PAM JIT elevation feature in Devolutions Server 2025.1.5.0 and earlier allows a PAM us...
CVE-2025-36558MEDIUM6.1KUNBUS PiCtory version 2.11.1 and earlier are vulnerable to a cross-site-scripting attack via the sso_token used for aut...
CVE-2025-46565MEDIUM5.3Vite is a frontend tooling framework for javascript. Prior to versions 6.3.4, 6.2.7, 6.1.6, 5.4.19, and 4.5.14, the cont...
CVE-2025-46345MEDIUM6.9Auth0 Account Link Extension is an extension aimed to help link accounts easily. Versions 2.3.4 to 2.6.6 do not verify t...
CVE-2025-44867MEDIUM6.3Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetNetCheckTools function via th...
CVE-2025-44866MEDIUM6.3Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the lev...
CVE-2025-44865MEDIUM6.3Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the ena...
CVE-2025-44864MEDIUM6.3Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the mod...
CVE-2025-44863MEDIUM6.5TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process functio...
CVE-2025-44862MEDIUM6.3TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the recvUpgradeNewFw fu...
CVE-2025-44861MEDIUM6.3TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the CloudSrvUserdataVer...
CVE-2025-44860MEDIUM6.5TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process functio...
CVE-2025-32890MEDIUM6.5An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. It uses a custom implementation of e...
CVE-2025-32887MEDIUM6.5An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. A command channel includes the next ho...
CVE-2025-32886MEDIUM5.5An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. All packets sent over RF are also sent...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now