2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-61613HIGH7.5In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv...
CVE-2025-61612HIGH7.5In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv...
CVE-2025-61611HIGH7.5In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional ...
CVE-2025-41772HIGH7.5An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL ...
CVE-2025-41767HIGH7.2A high-privileged remote attacker can fully compromise the device by abusing an update signature bypass vulnerability in...
CVE-2025-41766HIGH8.8A low-privileged remote attacker can trigger a stack-based buffer overflow via a crafted HTTP POST request using the ubr...
CVE-2025-41765CRITICAL9.1Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupload.cgi endpoint to...
CVE-2025-41764CRITICAL9.1Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupdate.cgi endpoint to...
CVE-2025-41763MEDIUM6.5A low‑privileged remote attacker can directly interact with the wwwdnload.cgi endpoint to download any resource availabl...
CVE-2025-41762MEDIUM6.2An unauthenticated attacker can abuse the weak hash of the backup generated by the wwwdnload.cgi endpoint to gain unauth...
CVE-2025-41761HIGH7.8A low‑privileged local attacker who gains access to the UBR service account (e.g., via SSH) can escalate privileges to o...
CVE-2025-41760MEDIUM4.9An administrator may attempt to block all traffic by configuring a pass filter with an empty table. However, in UBR, an ...
CVE-2025-41759MEDIUM4.9An administrator may attempt to block all networks by specifying "\*" or "all" as the network identifier. However, these...
CVE-2025-41758HIGH8.8A low-privileged remote attacker can exploit an arbitrary file write vulnerability in the wwupload.cgi endpoint. Due to ...
CVE-2025-41757HIGH8.8A low-privileged remote attacker can abuse the backup restore functionality of UBR (ubr-restore) which runs with elevate...
CVE-2025-41756HIGH8.1A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpo...
CVE-2025-41755MEDIUM6.5A low-privileged remote attacker can exploit the ubr-logread method in wwwubr.cgi to read arbitrary files on the system....
CVE-2025-41754MEDIUM6.5A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpo...
CVE-2025-14675HIGH7.2The Meta Box plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in t...
CVE-2025-8899HIGH8.8The Paid Videochat Turnkey Site – HTML5 PPV Live Webcams plugin for WordPress is vulnerable to Privilege Escalation in a...
CVE-2025-14353HIGH7.5The ZIP Code Based Content Protection plugin for WordPress is vulnerable to SQL Injection in all versions up to, and inc...
CVE-2025-69654HIGH7.5A crafted JavaScript input executed with the QuickJS release 2025-09-13, fixed in commit fcd33c1afa7b3028531f53cd1190a38...
CVE-2025-69653MEDIUM6.5A crafted JavaScript input can trigger an internal assertion failure in QuickJS release 2025-09-13, fixed in commit 1dbb...
CVE-2025-69652MEDIUM6.2GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF b...
CVE-2025-69650HIGH7.5GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now