2025 CVE Vulnerabilities

45,223 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-20714HIGH7.8In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es...
CVE-2025-20713HIGH7.8In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es...
CVE-2025-20712HIGH8.8In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (...
CVE-2025-20711HIGH8.8In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (...
CVE-2025-20710HIGH8.8In wlan AP driver, there is a possible out of bounds write due to an integer overflow. This could lead to remote (proxim...
CVE-2025-20709HIGH8.8In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (...
CVE-2025-10228HIGH8.8Session Fixation vulnerability in Rolantis Information Technologies Agentis allows Session Hijacking. This issue affect...
CVE-2025-46581CRITICAL9.8ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can ...
CVE-2025-41718HIGH7.5A cleartext transmission of sensitive information vulnerability in the affected products allows an unauthorized remote a...
CVE-2025-41699HIGH8.8An low privileged remote attacker with an account for the Web-based management can change the system configuration to pe...
CVE-2025-55078MEDIUM5.5In Eclipse ThreadX before version 6.4.3, an attacker can cause a denial of service (crash) by providing a pointer to a r...
CVE-2025-41707MEDIUM5.3The websocket handler is vulnerable to a denial of service condition. An unauthenticated remote attacker can send a craf...
CVE-2025-41706MEDIUM5.3The webserver is vulnerable to a denial of service condition. An unauthenticated remote attacker can craft a special GET...
CVE-2025-41705MEDIUM6.8An unauthenticated remote attacker (MITM) can intercept the websocket messages to gain access to the login credentials f...
CVE-2025-41704MEDIUM5.3An unauthanticated remote attacker can perform a DoS of the Modbus service by sending a specific function and sub-functi...
CVE-2025-41703HIGH7.5An unauthenticated remote attacker can cause a Denial of Service by turning off the output of the UPS via Modbus command...
CVE-2025-8594LOW3.8The Pz-LinkCard WordPress plugin before 2.5.7 does not validate a parameter before making a request to it, which could a...
CVE-2025-59889HIGH8.6Improper authentication of library files in the Eaton IPP software installer could lead to arbitrary code execution of a...
CVE-2025-11731LOW3.1A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during sty...
CVE-2025-10732MEDIUM4.3The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Information Dis...
CVE-2025-10357MEDIUM6.1The Simple SEO WordPress plugin before 2.0.32 does not sanitise and escape some parameters when outputing them in the pa...
CVE-2025-42939MEDIUM4.3SAP S/4HANA (Manage Processing Rules - For Bank Statements) allows an authenticated attacker with basic privileges to de...
CVE-2025-42937CRITICAL9.8SAP Print Service (SAPSprint) performs insufficient validation of path information provided by users. An unauthenticated...
CVE-2025-42910CRITICAL9Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attack...
CVE-2025-42909LOW3SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default p...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now