2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-70330LOW3.3Easy Grade Pro 4.1.0.2 contains a file parsing logic flaw in the handling of proprietary .EGP gradebook files. By modify...
CVE-2025-70027HIGH7.5An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. This ...
CVE-2025-67298HIGH8.1An issue in ClasroomIO before v.0.2.6 allows a remote attacker to escalate privileges via the endpoints /api/verify and ...
CVE-2025-13067HIGH8.8The Royal Addons for Elementor plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and in...
CVE-2025-12473MEDIUM6.1The RTMKit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'themebuilder' parameter in all ...
CVE-2025-22850MEDIUM5.6Time-of-check time-of-use race condition in the UEFI PdaSmm module for some Intel(R) reference platforms may allow an in...
CVE-2025-22444MEDIUM5.6Exposure of resource to wrong sphere in the UEFI PdaSmm module for some Intel(R) reference platforms may allow an inform...
CVE-2025-20105HIGH8.7Improper input validation in some UEFI firmware SMM module for the Intel(R) reference platforms may allow an escalation ...
CVE-2025-20096MEDIUM5.9Improper input validation in the UEFI firmware for some Intel Reference Platforms may allow an escalation of privilege. ...
CVE-2025-20073LOW1.8Improper buffer restrictions in the UEFI DXE module for some Intel(R) Reference Platforms within UEFI may allow an infor...
CVE-2025-20068HIGH7.1Improper input validation in the UEFI ImcErrorHandler module for some Intel(R) reference platforms may allow an escalati...
CVE-2025-20064HIGH8.7Improper input validation in the UEFI FlashUcAcmSmm module for some Intel(R) reference platforms may allow an escalation...
CVE-2025-20028HIGH7.1Time-of-check time-of-use race condition in the WheaERST SMM module for some Intel(R) reference platforms may allow an e...
CVE-2025-20027HIGH7.1Improper input validation in the UEFI WheaERST module for some Intel(R) reference platforms may allow an escalation of p...
CVE-2025-20005MEDIUM5.6Improper buffer restrictions in some UEFI firmware for some Intel(R) reference platforms may allow an escalation of priv...
CVE-2025-70802HIGH8.4Tenda G1V3.1si V16.01.7.8 Firmware V16.01.7.8 was discovered to contain a hardcoded password vulnerability in /etc_ro/sh...
CVE-2025-70798HIGH8.4Tenda i24V3.0si V3.0.0.5 Firmware V3.0.0.5 was discovered to contain a hardcoded password vulnerability in /etc_ro/shado...
CVE-2025-70244HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formWlanSetup.
CVE-2025-66413MEDIUM6.5Git for Windows is the Windows port of Git. Prior to 2.53.0(2), it is possible to obtain a user's NTLM hash by tricking ...
CVE-2025-36920HIGH8.4In hyp_alloc of arch/arm64/kvm/hyp/nvhe/alloc.c, there is a possible out of bounds write due to improper input validatio...
CVE-2025-13213MEDIUM5.4IBM Aspera Orchestrator 3.0.0 through 4.1.2 is vulnerable to HTTP header injection, caused by improper validation of inp...
CVE-2025-70251HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formWlanGuestSetup.
CVE-2025-70249HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizard2.
CVE-2025-70247HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizard1.
CVE-2025-70246HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formVirtualServ.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now