2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-70050MEDIUM6.5An issue pertaining to CWE-312: Cleartext Storage of Sensitive Information was discovered in lesspass lesspass v9.6.9 wh...
CVE-2025-70048HIGH7.5An issue pertaining to CWE-319: Cleartext Transmission of Sensitive Information was discovered in Nexusoft NexusInterfac...
CVE-2025-70047HIGH7.5An issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in Nexusoft NexusInterface v3.2.0-beta....
CVE-2025-70046CRITICAL9.8An issue pertaining to CWE-829: Inclusion of Functionality from Untrusted Control Sphere was discovered in Miazzy oa-fro...
CVE-2025-70042CRITICAL9.8An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in oslabs-beta ThermaKube master.
CVE-2025-70040MEDIUM5.3An issue pertaining to CWE-532: Insertion of Sensitive Information into Log File was discovered in LupinLin1 jimeng-web-...
CVE-2025-70250HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formdumpeasysetup.
CVE-2025-70243HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard534.
CVE-2025-70238HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard52.
CVE-2025-70059HIGH7.5An issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in YMFE yapi v1.12.0 and allows attacke...
CVE-2025-69648MEDIUM6.2GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malfor...
CVE-2025-69647MEDIUM6.2GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malfor...
CVE-2025-15576HIGH7.5If two sibling jails are restricted to separate filesystem trees, which is to say that neither of the two jail root dire...
CVE-2025-15547HIGH8.8By default, jailed processes cannot mount filesystems, including nullfs(4). However, the allow.mount.nullfs option enab...
CVE-2025-14769HIGH7.5In some cases, the `tcp-setmss` handler may free the packet data and throw an error without halting the rule processing ...
CVE-2025-14558HIGH7.2The rtsol(8) and rtsold(8) programs do not validate the domain search list options provided in router advertisement mess...
CVE-2025-69219HIGH8.8A user with access to the DB could craft a database entry that would result in executing code on Triggerer - which gives...
CVE-2025-40639CRITICAL9.8A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, up...
CVE-2025-40638MEDIUM6.1A reflected Cross-Site Scripting (XSS) vulnerability has been found in Eventobot. This vulnerability allows an attacker...
CVE-2025-33022Rejected reason: The reporter agreed to not assign CVE ID
CVE-2025-69279HIGH7.5In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv...
CVE-2025-69278HIGH7.5In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv...
CVE-2025-61616HIGH7.5In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv...
CVE-2025-61615HIGH7.5In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv...
CVE-2025-61614HIGH7.5In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now