2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-54001CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeREX Classter classter allows Object Injection.This issue affects...
CVE-2025-53335HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-40931CRITICAL9.1Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id. Apache::Session::Generate::MD...
CVE-2025-40926CRITICAL9.8Plack::Middleware::Session::Simple versions before 0.05 for Perl generates session ids insecurely. The default session ...
CVE-2025-41257MEDIUM4.8Suprema’s BioStar 2 in version 2.9.11.6 allows users to set new password without providing the current one. Exploiting t...
CVE-2025-70222CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin,goform/getAuth...
CVE-2025-68467LOW3.4Dark Reader is an accessibility browser extension that makes web pages colors dark. The dynamic dark mode feature of the...
CVE-2025-66024CRITICAL9The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions starting with 9....
CVE-2025-70225CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curtime parameter to the goform/formEasySetupWWConfi...
CVE-2025-70221CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin.
CVE-2025-46108CRITICAL9.8D-link Dir-513 A1FW110 is vulnerable to Buffer Overflow in the function formTcpipSetup.
CVE-2025-70219CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the goform/formDeviceReboot.
CVE-2025-70226CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formEasySetupWizard.
CVE-2025-70223CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAdvNetwork.
CVE-2025-70220CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAutoDetecWAN_wizard4...
CVE-2025-70218CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via POST to the goform/formAdvFirewall component.
CVE-2025-69969CRITICAL9.6A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Po...
CVE-2025-66944CRITICAL9.8SQL Injection vulnerability in vran-dev databaseir v.1.0.7 and before allows a remote attacker to execute arbitrary code...
CVE-2025-66678CRITICAL9.8An issue in the HwRwDrv.sys component of Nil Hardware Editor Hardware Read & Write Utility v1.25.11.26 and earlier allow...
CVE-2025-15558HIGH8Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exis...
CVE-2025-62879MEDIUM4.9A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both acce...
CVE-2025-59787MEDIUM6.52N Access Commander application version 3.4.2 and prior returns HTTP 500 Internal Server Error responses when receiving ...
CVE-2025-59786CRITICAL9.82N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to ...
CVE-2025-59785HIGH7.2Improper validation of API end-point in 2N Access Commander version 3.4.2 and prior allows attacker to bypass password p...
CVE-2025-59784HIGH7.22N Access Commander version 3.4.1 and prior is vulnerable to log pollution. Certain parameters sent over API may be incl...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now