2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32885 | MEDIUM | 6.5 | 0.2% | May 1, 2025 | An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The app there makes it possible to inj... |
| CVE-2025-32884 | MEDIUM | 6.5 | 0.1% | May 1, 2025 | An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. By default, a GID is the user's phon... |
| CVE-2025-32882 | MEDIUM | 6.5 | 0.1% | May 1, 2025 | An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The app uses a custom implementation o... |
| CVE-2025-32881 | MEDIUM | 6.5 | 0.1% | May 1, 2025 | An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. By default, the GID is the user's phon... |
| CVE-2025-44848 | MEDIUM | 6.5 | 0.9% | May 1, 2025 | TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the msg_process functi... |
| CVE-2025-44847 | MEDIUM | 6.3 | 0.9% | May 1, 2025 | TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the setWebWlanIdx func... |
| CVE-2025-44846 | MEDIUM | 6.3 | 0.9% | May 1, 2025 | TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the recvUpgradeNewFw f... |
| CVE-2025-44845 | MEDIUM | 6.5 | 0.9% | May 1, 2025 | TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the NTPSyncWithHost fu... |
| CVE-2025-44844 | MEDIUM | 6.5 | 0.9% | May 1, 2025 | TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the setUpgradeFW funct... |
| CVE-2025-44843 | MEDIUM | 6.5 | 1.0% | May 1, 2025 | TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVe... |
| CVE-2025-44842 | MEDIUM | 6.5 | 0.9% | May 1, 2025 | TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the msg_process functi... |
| CVE-2025-44841 | MEDIUM | 6.5 | 0.9% | May 1, 2025 | TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVe... |
| CVE-2025-44840 | MEDIUM | 6.5 | 0.9% | May 1, 2025 | TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVe... |
| CVE-2025-44839 | MEDIUM | 6.5 | 0.9% | May 1, 2025 | TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVe... |
| CVE-2025-44838 | MEDIUM | 6.3 | 0.9% | May 1, 2025 | TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the setUploadUser... |
| CVE-2025-44837 | MEDIUM | 6.3 | 0.9% | May 1, 2025 | TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the CloudSrvUserd... |
| CVE-2025-44836 | MEDIUM | 6.3 | 0.9% | May 1, 2025 | TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the setApRebootSc... |
| CVE-2025-23246 | MEDIUM | 5.5 | 0.1% | May 1, 2025 | NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it a... |
| CVE-2025-44854 | MEDIUM | 6.3 | 0.9% | May 1, 2025 | TOTOLINK CP900 V6.3c.1144_B20190715 was found to contain a command injection vulnerability in the setUpgradeUboot functi... |
| CVE-2025-44835 | MEDIUM | 6.3 | 1.1% | May 1, 2025 | D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in iptablesWebsFilterRun, which allows remote attack... |
| CVE-2025-37794 | MEDIUM | 5.5 | 0.2% | May 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: Purge vif txq in ieee80211_do_stop(... |
| CVE-2025-37793 | MEDIUM | 5.5 | 0.1% | May 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: avs: Fix null-ptr-deref in avs_compone... |
| CVE-2025-37792 | MEDIUM | 5.5 | 0.2% | May 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btrtl: Prevent potential NULL dereferenc... |
| CVE-2025-37791 | MEDIUM | 5.5 | 0.2% | May 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: ethtool: cmis_cdb: use correct rpl size in ethtool_... |
| CVE-2025-37790 | MEDIUM | 5.5 | 0.2% | May 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: mctp: Set SOCK_RCU_FREE Bind lookup runs unde... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now