2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-70340MEDIUM6.5A Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms ...
CVE-2025-70293CRITICAL9.8An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_b...
CVE-2025-70290CRITICAL9.8An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support c...
CVE-2025-61165CRITICAL9.8An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attac...
CVE-2025-61164HIGH7.5Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint.
CVE-2025-61163CRITICAL9.8Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This...
CVE-2025-61162HIGH7.5Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user info via a crafted req...
CVE-2025-56798HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows ...
CVE-2025-29419HIGH7.1CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack.
CVE-2025-10903MEDIUM6.5GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 19.1.7, 19.2 before 19.2.5, and 19....
CVE-2025-71407——Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2025-71406——Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2025-71346——Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2025-41741——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-9878MEDIUM6.4The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Stored Cr...
CVE-2025-26238HIGH8.1In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code.
CVE-2025-26237HIGH8.1D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of msp_info, which can b...
CVE-2025-36940HIGH8.8Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from U...
CVE-2025-36939MEDIUM5.7Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread net...
CVE-2025-68825HIGH7.5HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, conta...
CVE-2025-68833MEDIUM5.3HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker u...
CVE-2025-63080HIGH8.5Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC requests and perform o...
CVE-2025-3127——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-2795——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-15671MEDIUM5.4The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and s...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now