2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40926 | CRITICAL | 9.8 | 0.4% | Mar 5, 2026 | Plack::Middleware::Session::Simple versions before 0.05 for Perl generates session ids insecurely. The default session ... |
| CVE-2025-41257 | MEDIUM | 4.8 | 0.2% | Mar 4, 2026 | Suprema’s BioStar 2 in version 2.9.11.6 allows users to set new password without providing the current one. Exploiting t... |
| CVE-2025-70222 | CRITICAL | 9.8 | 0.5% | Mar 4, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin,goform/getAuth... |
| CVE-2025-68467 | LOW | 3.4 | 0.1% | Mar 4, 2026 | Dark Reader is an accessibility browser extension that makes web pages colors dark. The dynamic dark mode feature of the... |
| CVE-2025-66024 | CRITICAL | 9 | 0.4% | Mar 4, 2026 | The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions starting with 9.... |
| CVE-2025-70225 | CRITICAL | 9.8 | 0.5% | Mar 4, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curtime parameter to the goform/formEasySetupWWConfi... |
| CVE-2025-70221 | CRITICAL | 9.8 | 0.5% | Mar 4, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin. |
| CVE-2025-46108 | CRITICAL | 9.8 | 0.6% | Mar 4, 2026 | D-link Dir-513 A1FW110 is vulnerable to Buffer Overflow in the function formTcpipSetup. |
| CVE-2025-70219 | CRITICAL | 9.8 | 0.5% | Mar 4, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the goform/formDeviceReboot. |
| CVE-2025-70226 | CRITICAL | 9.8 | 0.5% | Mar 4, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formEasySetupWizard. |
| CVE-2025-70223 | CRITICAL | 9.8 | 0.5% | Mar 4, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAdvNetwork. |
| CVE-2025-70220 | CRITICAL | 9.8 | 0.6% | Mar 4, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAutoDetecWAN_wizard4... |
| CVE-2025-70218 | CRITICAL | 9.8 | 0.6% | Mar 4, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via POST to the goform/formAdvFirewall component. |
| CVE-2025-69969 | CRITICAL | 9.6 | 0.5% | Mar 4, 2026 | A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Po... |
| CVE-2025-66944 | CRITICAL | 9.8 | 0.8% | Mar 4, 2026 | SQL Injection vulnerability in vran-dev databaseir v.1.0.7 and before allows a remote attacker to execute arbitrary code... |
| CVE-2025-66678 | CRITICAL | 9.8 | 0.6% | Mar 4, 2026 | An issue in the HwRwDrv.sys component of Nil Hardware Editor Hardware Read & Write Utility v1.25.11.26 and earlier allow... |
| CVE-2025-15558 | HIGH | 8 | 0.5% | Mar 4, 2026 | Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exis... |
| CVE-2025-62879 | MEDIUM | 4.9 | 0.3% | Mar 4, 2026 | A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both acce... |
| CVE-2025-59787 | MEDIUM | 6.5 | 0.2% | Mar 4, 2026 | 2N Access Commander application version 3.4.2 and prior returns HTTP 500 Internal Server Error responses when receiving ... |
| CVE-2025-59786 | CRITICAL | 9.8 | 0.3% | Mar 4, 2026 | 2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to ... |
| CVE-2025-59785 | HIGH | 7.2 | 0.2% | Mar 4, 2026 | Improper validation of API end-point in 2N Access Commander version 3.4.2 and prior allows attacker to bypass password p... |
| CVE-2025-59784 | HIGH | 7.2 | 0.3% | Mar 4, 2026 | 2N Access Commander version 3.4.1 and prior is vulnerable to log pollution. Certain parameters sent over API may be incl... |
| CVE-2025-59783 | HIGH | 7.2 | 0.9% | Mar 4, 2026 | API endpoint for user synchronization in 2N Access Commander version 3.4.1 did not have a sufficient input validation al... |
| CVE-2025-12801 | MEDIUM | 6.5 | 0.5% | Mar 4, 2026 | A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3... |
| CVE-2025-71238 | HIGH | 7.8 | 0.2% | Mar 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix bsg_done() causing double free ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now