2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61613 | HIGH | 7.5 | 0.3% | Mar 9, 2026 | In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv... |
| CVE-2025-61612 | HIGH | 7.5 | 0.3% | Mar 9, 2026 | In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv... |
| CVE-2025-61611 | HIGH | 7.5 | 0.6% | Mar 9, 2026 | In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional ... |
| CVE-2025-41772 | HIGH | 7.5 | 0.3% | Mar 9, 2026 | An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL ... |
| CVE-2025-41767 | HIGH | 7.2 | 0.2% | Mar 9, 2026 | A high-privileged remote attacker can fully compromise the device by abusing an update signature bypass vulnerability in... |
| CVE-2025-41766 | HIGH | 8.8 | 0.5% | Mar 9, 2026 | A low-privileged remote attacker can trigger a stack-based buffer overflow via a crafted HTTP POST request using the ubr... |
| CVE-2025-41765 | CRITICAL | 9.1 | 0.3% | Mar 9, 2026 | Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupload.cgi endpoint to... |
| CVE-2025-41764 | CRITICAL | 9.1 | 0.4% | Mar 9, 2026 | Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupdate.cgi endpoint to... |
| CVE-2025-41763 | MEDIUM | 6.5 | 0.2% | Mar 9, 2026 | A low‑privileged remote attacker can directly interact with the wwwdnload.cgi endpoint to download any resource availabl... |
| CVE-2025-41762 | MEDIUM | 6.2 | 0.1% | Mar 9, 2026 | An unauthenticated attacker can abuse the weak hash of the backup generated by the wwwdnload.cgi endpoint to gain unauth... |
| CVE-2025-41761 | HIGH | 7.8 | 0.2% | Mar 9, 2026 | A low‑privileged local attacker who gains access to the UBR service account (e.g., via SSH) can escalate privileges to o... |
| CVE-2025-41760 | MEDIUM | 4.9 | 0.3% | Mar 9, 2026 | An administrator may attempt to block all traffic by configuring a pass filter with an empty table. However, in UBR, an ... |
| CVE-2025-41759 | MEDIUM | 4.9 | 0.3% | Mar 9, 2026 | An administrator may attempt to block all networks by specifying "\*" or "all" as the network identifier. However, these... |
| CVE-2025-41758 | HIGH | 8.8 | 0.5% | Mar 9, 2026 | A low-privileged remote attacker can exploit an arbitrary file write vulnerability in the wwupload.cgi endpoint. Due to ... |
| CVE-2025-41757 | HIGH | 8.8 | 0.5% | Mar 9, 2026 | A low-privileged remote attacker can abuse the backup restore functionality of UBR (ubr-restore) which runs with elevate... |
| CVE-2025-41756 | HIGH | 8.1 | 0.3% | Mar 9, 2026 | A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpo... |
| CVE-2025-41755 | MEDIUM | 6.5 | 0.5% | Mar 9, 2026 | A low-privileged remote attacker can exploit the ubr-logread method in wwwubr.cgi to read arbitrary files on the system.... |
| CVE-2025-41754 | MEDIUM | 6.5 | 0.3% | Mar 9, 2026 | A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpo... |
| CVE-2025-14675 | HIGH | 7.2 | 0.7% | Mar 7, 2026 | The Meta Box plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in t... |
| CVE-2025-8899 | HIGH | 8.8 | 0.4% | Mar 7, 2026 | The Paid Videochat Turnkey Site – HTML5 PPV Live Webcams plugin for WordPress is vulnerable to Privilege Escalation in a... |
| CVE-2025-14353 | HIGH | 7.5 | 0.3% | Mar 7, 2026 | The ZIP Code Based Content Protection plugin for WordPress is vulnerable to SQL Injection in all versions up to, and inc... |
| CVE-2025-69654 | HIGH | 7.5 | 0.3% | Mar 6, 2026 | A crafted JavaScript input executed with the QuickJS release 2025-09-13, fixed in commit fcd33c1afa7b3028531f53cd1190a38... |
| CVE-2025-69653 | MEDIUM | 6.5 | 0.2% | Mar 6, 2026 | A crafted JavaScript input can trigger an internal assertion failure in QuickJS release 2025-09-13, fixed in commit 1dbb... |
| CVE-2025-69652 | MEDIUM | 6.2 | 0.2% | Mar 6, 2026 | GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF b... |
| CVE-2025-69650 | HIGH | 7.5 | 0.5% | Mar 6, 2026 | GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now