2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-22018MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: atm: Fix NULL pointer dereference When MPOA_cache_...
CVE-2025-3666MEDIUM6.9A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. Affected by this issue is...
CVE-2025-3665MEDIUM6.9A vulnerability has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. Affected by this vul...
CVE-2025-3664MEDIUM6.9A vulnerability, which was classified as critical, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is the f...
CVE-2025-2314MEDIUM6.4The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v...
CVE-2025-32385MEDIUM6.5EspoCRM is an Open Source Customer Relationship Management software. Prior to 9.0.5, Iframe dashlet allows user to displ...
CVE-2025-32388MEDIUM5.4SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.20.6 , unsa...
CVE-2025-25458MEDIUM4.6Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2.
CVE-2025-25453MEDIUM4.6Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serviceName2.
CVE-2025-22911MEDIUM5.6RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formiNICbasicREP function.
CVE-2025-32782MEDIUM5.3Ash Authentication provides authentication for the Ash framework. The confirmation flow for account creation currently u...
CVE-2025-31950MEDIUM6.9An unauthenticated attacker can obtain EV charger energy consumption information of other users.
CVE-2025-31945MEDIUM6.9An unauthenticated attacker can obtain other users' charger information.
CVE-2025-31654MEDIUM6.9An attacker can get information about the groups of the smart home devices for arbitrary users (i.e., "rooms").
CVE-2025-31147MEDIUM6.9Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users.
CVE-2025-30982MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookPr...
CVE-2025-30966MEDIUM5.4Path Traversal vulnerability in NotFound WPJobBoard allows Path Traversal. This issue affects WPJobBoard: from n/a throu...
CVE-2025-30512MEDIUM6.9Unauthenticated attackers can send configuration settings to device and possible perform physical actions remotely (e.g....
CVE-2025-30257MEDIUM6.9Unauthenticated attackers can retrieve serial number of smart meters associated to a specific user account.
CVE-2025-27929MEDIUM6.9Unauthenticated attackers can retrieve full list of users associated with arbitrary accounts.
CVE-2025-27927MEDIUM6.9An unauthenticated attackers can obtain a list of smart devices by knowing a valid username through an unprotected API.
CVE-2025-27892MEDIUM6.8Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE:...
CVE-2025-27719MEDIUM6.9Unauthenticated attackers can query an API endpoint and get device details.
CVE-2025-27575MEDIUM6.9An unauthenticated attacker can obtain EV charger version and firmware upgrading history by knowing the charger ID.
CVE-2025-27565MEDIUM5.3An unauthenticated attacker can delete any user's "rooms" by knowing the user's and room IDs.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now