2025 CVE Vulnerabilities

45,139 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-22444MEDIUM5.6Exposure of resource to wrong sphere in the UEFI PdaSmm module for some Intel(R) reference platforms may allow an inform...
CVE-2025-20105HIGH8.7Improper input validation in some UEFI firmware SMM module for the Intel(R) reference platforms may allow an escalation ...
CVE-2025-20096MEDIUM5.9Improper input validation in the UEFI firmware for some Intel Reference Platforms may allow an escalation of privilege. ...
CVE-2025-20073LOW1.8Improper buffer restrictions in the UEFI DXE module for some Intel(R) Reference Platforms within UEFI may allow an infor...
CVE-2025-20068HIGH7.1Improper input validation in the UEFI ImcErrorHandler module for some Intel(R) reference platforms may allow an escalati...
CVE-2025-20064HIGH8.7Improper input validation in the UEFI FlashUcAcmSmm module for some Intel(R) reference platforms may allow an escalation...
CVE-2025-20028HIGH7.1Time-of-check time-of-use race condition in the WheaERST SMM module for some Intel(R) reference platforms may allow an e...
CVE-2025-20027HIGH7.1Improper input validation in the UEFI WheaERST module for some Intel(R) reference platforms may allow an escalation of p...
CVE-2025-20005MEDIUM5.6Improper buffer restrictions in some UEFI firmware for some Intel(R) reference platforms may allow an escalation of priv...
CVE-2025-70802HIGH8.4Tenda G1V3.1si V16.01.7.8 Firmware V16.01.7.8 was discovered to contain a hardcoded password vulnerability in /etc_ro/sh...
CVE-2025-70798HIGH8.4Tenda i24V3.0si V3.0.0.5 Firmware V3.0.0.5 was discovered to contain a hardcoded password vulnerability in /etc_ro/shado...
CVE-2025-70244HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formWlanSetup.
CVE-2025-66413MEDIUM6.5Git for Windows is the Windows port of Git. Prior to 2.53.0(2), it is possible to obtain a user's NTLM hash by tricking ...
CVE-2025-36920HIGH8.4In hyp_alloc of arch/arm64/kvm/hyp/nvhe/alloc.c, there is a possible out of bounds write due to improper input validatio...
CVE-2025-13213MEDIUM5.4IBM Aspera Orchestrator 3.0.0 through 4.1.2 is vulnerable to HTTP header injection, caused by improper validation of inp...
CVE-2025-70251HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formWlanGuestSetup.
CVE-2025-70249HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizard2.
CVE-2025-70247HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizard1.
CVE-2025-70246HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formVirtualServ.
CVE-2025-70242HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formSetWanPPTP.
CVE-2025-70227HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the nextPage parameter to goform/formLanguageChange.
CVE-2025-70129MEDIUM5.3If the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generate...
CVE-2025-70128MEDIUM6.1A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8....
CVE-2025-48611HIGH7.8In DeviceId of DeviceId.java, there is a possible desync in persistence due to a missing bounds check. This could lead t...
CVE-2025-36227MEDIUM5.4IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to HTTP header injection, caused by improper validation of inpu...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now