2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-66052HIGH7.2Vivotek IP7137 camera with firmware version 0200a is vulnerable to command injection. Parameter "system_ntpIt" used by "...
CVE-2025-66049HIGH7.5Vivotek IP7137 camera with firmware version 0200a is vulnerable to an information disclosure issue where live camera foo...
CVE-2025-64092HIGH7.5This vulnerability allows unauthenticated attackers to inject an SQL request into GET request parameters and directly qu...
CVE-2025-64091HIGH8.8This vulnerability allows authenticated attackers to execute commands via the NTP-configuration of the device.
CVE-2025-64090HIGH8.8This vulnerability allows authenticated attackers to execute commands via the hostname of the device.
CVE-2025-69195HIGH8.8A flaw was found in GNU Wget2. This vulnerability, a stack-based buffer overflow, occurs in the filename sanitization lo...
CVE-2025-14937HIGH7.2The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acff' parame...
CVE-2025-14657HIGH7.2The Eventin – Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress is vulnerable to unau...
CVE-2025-15057HIGH7.2The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fh` (fingerprint) para...
CVE-2025-15055HIGH7.2The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' and 'resource' ...
CVE-2025-66315HIGH8.8There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper director...
CVE-2025-14436HIGH7.2The Brevo for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_connection_id’...
CVE-2025-68719HIGH8.8KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 mishandle configuration management. Once any user is logged in and main...
CVE-2025-68716HIGH8.4KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the SSH service enabled by default on the LAN interface. The roo...
CVE-2025-15464HIGH7.5Exported Activity allows external applications to gain application context and directly launch Gmail with inbox access, ...
CVE-2025-65518HIGH7.5Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability e...
CVE-2025-68158HIGH8.8Authlib is a Python library which builds OAuth and OpenID Connect servers. In versions 1.0.0 through 1.6.5, cache-backed...
CVE-2025-56424HIGH7.5An issue in Insiders Technologies GmbH e-invoice pro before release 1 Service Pack 2 allows a remote attacker to cause a...
CVE-2025-50334HIGH7.5An issue in Technitium DNS Server v.13.5 allows a remote attacker to cause a denial of service via the rate-limiting com...
CVE-2025-68151HIGH7.5CoreDNS is a DNS server that chains plugins. Prior to version 1.14.0, multiple CoreDNS server implementations (gRPC, HTT...
CVE-2025-67858HIGH7A Improper Neutralization of Argument Delimiters vulnerability in Foomuuri can lead to integrity loss of the firewall co...
CVE-2025-67089HIGH8.1A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present ...
CVE-2025-63611HIGH8.7Cross-Site Scripting in phpgurukul Hostel Management System v2.1 user-provided complaint fields (Explain the Complaint) ...
CVE-2025-66003HIGH7.3An External Control of File Name or Path vulnerability in smb4k allowsl ocal users to perform a local root exploit via s...
CVE-2025-14025HIGH8.5A flaw was found in Ansible Automation Platform (AAP). Read-only scoped OAuth2 API Tokens in AAP, are enforced at the Ga...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now