2025 CVE Vulnerabilities

45,244 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-59034MEDIUM4.3Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior t...
CVE-2025-58764CRITICAL9.8Claude Code is an agentic coding tool. Due to an error in command parsing, versions prior to 1.0.105 were vulnerable to ...
CVE-2025-57573MEDIUM5.6Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the wifiTimeClose parameter in goform/setWifi...
CVE-2025-57572MEDIUM5.6Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the onlineList parameter in goform/setParentC...
CVE-2025-57571MEDIUM5.6Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow. via the macFilterList parameter in goform/setNAT...
CVE-2025-57570MEDIUM5.6Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the QosList parameter in goform/setQoS.
CVE-2025-57569MEDIUM5.6Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the portList parameter in /goform/setNAT.
CVE-2025-43938MEDIUM4.4Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Plaintext Storage of a Password vulnera...
CVE-2025-43888HIGH7.8Dell PowerProtect Data Manager, Hyper-V, version(s) 19.19 and 19.20, contain(s) an Insertion of Sensitive Information in...
CVE-2025-43887HIGH7.8Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Incorrect Default Permissions vulnerab...
CVE-2025-43886MEDIUM4.4Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Path Traversal: '.../...//' vulnerabili...
CVE-2025-43885HIGH7.8Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Ele...
CVE-2025-43884MEDIUM6.7Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Ele...
CVE-2025-43725HIGH7.8Dell PowerProtect Data Manager, Generic Application Agent, version(s) 19.19 and 19.20, contain(s) an Incorrect Default P...
CVE-2025-29592MEDIUM5.6oasys v1.1 is vulnerable to Directory Traversal in ProcedureController.
CVE-2025-20340HIGH7.4A vulnerability in the Address Resolution Protocol (ARP) implementation of Cisco IOS XR Software could allow an unauthen...
CVE-2025-20248MEDIUM6A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker to byp...
CVE-2025-20159MEDIUM5.3A vulnerability in the management interface access control list (ACL) processing feature in Cisco IOS XR Software could ...
CVE-2025-56578MEDIUM5.7An issue in RTSPtoWeb v.2.4.3 allows a remote attacker to obtain sensitive information and executearbitrary code via the...
CVE-2025-56466HIGH7.5Hardcoded credentials in Dietly v1.25.0 for android allows attackers to gain sensitive information.
CVE-2025-56413HIGH8.8OS Command injection vulnerability in function OperateSSH in 1panel 2.0.8 allowing attackers to execute arbitrary comman...
CVE-2025-56407HIGH8.8A vulnerability has been found in HuangDou UTCMS V9 and classified as critical. This vulnerability affects the function ...
CVE-2025-56406HIGH7.5An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary comma...
CVE-2025-56405HIGH7.5An issue was discovered in litmusautomation litmus-mcp-server thru 0.0.1 allowing unauthorized attackers to control the ...
CVE-2025-56404HIGH7.5An issue was discovered in MariaDB MCP 0.1.0 allowing attackers to gain sensitive information via the SSE service as the...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now