2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-40926CRITICAL9.8Plack::Middleware::Session::Simple versions before 0.05 for Perl generates session ids insecurely. The default session ...
CVE-2025-41257MEDIUM4.8Suprema’s BioStar 2 in version 2.9.11.6 allows users to set new password without providing the current one. Exploiting t...
CVE-2025-70222CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin,goform/getAuth...
CVE-2025-68467LOW3.4Dark Reader is an accessibility browser extension that makes web pages colors dark. The dynamic dark mode feature of the...
CVE-2025-66024CRITICAL9The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions starting with 9....
CVE-2025-70225CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curtime parameter to the goform/formEasySetupWWConfi...
CVE-2025-70221CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin.
CVE-2025-46108CRITICAL9.8D-link Dir-513 A1FW110 is vulnerable to Buffer Overflow in the function formTcpipSetup.
CVE-2025-70219CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the goform/formDeviceReboot.
CVE-2025-70226CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formEasySetupWizard.
CVE-2025-70223CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAdvNetwork.
CVE-2025-70220CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAutoDetecWAN_wizard4...
CVE-2025-70218CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via POST to the goform/formAdvFirewall component.
CVE-2025-69969CRITICAL9.6A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Po...
CVE-2025-66944CRITICAL9.8SQL Injection vulnerability in vran-dev databaseir v.1.0.7 and before allows a remote attacker to execute arbitrary code...
CVE-2025-66678CRITICAL9.8An issue in the HwRwDrv.sys component of Nil Hardware Editor Hardware Read & Write Utility v1.25.11.26 and earlier allow...
CVE-2025-15558HIGH8Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exis...
CVE-2025-62879MEDIUM4.9A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both acce...
CVE-2025-59787MEDIUM6.52N Access Commander application version 3.4.2 and prior returns HTTP 500 Internal Server Error responses when receiving ...
CVE-2025-59786CRITICAL9.82N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to ...
CVE-2025-59785HIGH7.2Improper validation of API end-point in 2N Access Commander version 3.4.2 and prior allows attacker to bypass password p...
CVE-2025-59784HIGH7.22N Access Commander version 3.4.1 and prior is vulnerable to log pollution. Certain parameters sent over API may be incl...
CVE-2025-59783HIGH7.2API endpoint for user synchronization in 2N Access Commander version 3.4.1 did not have a sufficient input validation al...
CVE-2025-12801MEDIUM6.5A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3...
CVE-2025-71238HIGH7.8In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix bsg_done() causing double free ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now