2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-33181HIGH8.8NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could ...
CVE-2025-33180HIGH8.8NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could ...
CVE-2025-33179HIGH8.8NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could ...
CVE-2025-1789HIGH7.8Local privilege escalation in Genetec Update Service. An authenticated, low-privileged, Windows user could exploit this ...
CVE-2025-1787MEDIUM4.2Local admin could to leak information from the Genetec Update Service configuration web page. An authenticated, admin pr...
CVE-2025-62512MEDIUM5.3Piwigo is an open source photo gallery application for the web. In version 15.5.0 and likely earlier 15.x releases, the ...
CVE-2025-14963HIGH7.8A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the abil...
CVE-2025-13776HIGH7.1Multiple Finka programs use hard-coded Firebird database credentials (shared across all instances of this software). A m...
CVE-2025-69985CRITICAL9.8FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnera...
CVE-2025-63409HIGH8.8Privilege escalation and improper access control in GCOM EPON 1GE C00R371V00B01 allows remote authenticated users to mod...
CVE-2025-47904MEDIUM4.1Download of Code Without Integrity Check vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software ...
CVE-2025-67445HIGH7.5TOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of-service vulnerability in /cgi-bin/cstecgi.cgi. The CGI read...
CVE-2025-10010MEDIUM6.8The CPSD CryptoPro Secure Disk application boots a small Linux operating system to perform user authentication before us...
CVE-2025-14577CRITICAL9.8Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to e...
CVE-2025-27555MEDIUM6.5Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensiti...
CVE-2025-11165CRITICAL9.9A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users wit...
CVE-2025-40541HIGH7.2An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor...
CVE-2025-40540HIGH7.2A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arb...
CVE-2025-40539HIGH7.2A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arb...
CVE-2025-40538HIGH7.2A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to crea...
CVE-2025-15589HIGH7.2A vulnerability was determined in MuYuCMS 2.7. Affected is the function delete_dir_file of the file application/admin/co...
CVE-2025-15386HIGH8.8The Responsive Lightbox & Gallery WordPress plugin before 2.6.1 is vulnerable to an Unauthenticated Stored-XSS attack du...
CVE-2025-13943HIGH8.8A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware ...
CVE-2025-13942CRITICAL9.8A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C...
CVE-2025-11848MEDIUM4.9A null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version throu...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now