2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-26523HIGH7.4This vulnerability exists in RupeeWeb trading platform due to insufficient authorization controls on certain API endpoin...
CVE-2025-26522HIGH7.5This vulnerability exists in RupeeWeb trading platform due to improper implementation of OTP validation mechanism in cer...
CVE-2025-26788HIGH8.4StrongKey FIDO Server before 4.15.1 treats a non-discoverable (namedcredential) flow as a discoverable transaction.
CVE-2025-26519HIGH7musl libc 0.9.13 through 1.2.5 before 1.2.6 has an out-of-bounds write vulnerability when an attacker can trigger iconv ...
CVE-2025-22962HIGH7.2A critical remote code execution (RCE) vulnerability exists in the web-based management interface of GatesAir Maxiva UAX...
CVE-2025-22961HIGH8A critical information disclosure vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VA...
CVE-2025-22960HIGH8A session hijacking vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitter...
CVE-2025-26473HIGH7.5The Mojave Inverter uses the GET method for sensitive information.
CVE-2025-25281HIGH7.5An attacker may modify the URL to discover sensitive information about the target network.
CVE-2025-24836HIGH7.1With a specially crafted Python script, an attacker could send continuous startMeasurement commands over an unencrypted...
CVE-2025-22896HIGH7.5mySCADA myPRO Manager stores credentials in cleartext, which could allow an attacker to obtain sensitive information.
CVE-2025-24888HIGH8.1The SecureDrop Client is a desktop application for journalists to communicate with sources and work with submissions on ...
CVE-2025-25387HIGH7.2A SQL Injection vulnerability was found in /admin/manage-propertytype.php in PHPGurukul Land Record System v1.0, which a...
CVE-2025-26511HIGH8.8Systems running the Instaclustr fork of Stratio's Cassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0 through 4.0.16-...
CVE-2025-25901HIGH7.5A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11, triggered by the dnsserver1 and dnsserver2 par...
CVE-2025-25898HIGH7.5A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the pskSecret parameter at /userRpm/WlanSec...
CVE-2025-25897HIGH7.5A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the 'ip' parameter at /userRpm/WanStaticIpV...
CVE-2025-25357HIGH7.2A SQL Injection vulnerability was found in /admin/contactus.php in PHPGurukul Land Record System v1.0, which allows remo...
CVE-2025-25356HIGH7.2A SQL Injection vulnerability was found in /admin/bwdates-reports-details.php in PHPGurukul Land Record System v1.0, whi...
CVE-2025-25355HIGH7.2A SQL Injection vulnerability was found in /admin/bwdates-reports-details.php in PHPGurukul Land Record System v1.0, whi...
CVE-2025-25354HIGH7.2A SQL Injection was found in /admin/admin-profile.php in PHPGurukul Land Record System v1.0, which allows remote attacke...
CVE-2025-25352HIGH7.2A SQL Injection vulnerability was found in /admin/aboutus.php in PHPGurukul Land Record System v1.0, which allows remote...
CVE-2025-24904HIGH8.5libsignal-service-rs is a Rust version of the libsignal-service-java library which implements the core functionality to ...
CVE-2025-24903HIGH8.5libsignal-service-rs is a Rust version of the libsignal-service-java library which implements the core functionality to ...
CVE-2025-22480HIGH7.8Dell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability. A low-privileged...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now