2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-67159HIGH7.5Vatilon v1.12.37-20240124 was discovered to transmit user credentials in plaintext.
CVE-2025-67158HIGH7.5An authentication bypass in the /cgi-bin/jvsweb.cgi endpoint of Revotech I6032W-FHW v1.0.0014 - 20210517 allows attacker...
CVE-2025-9110HIGH7.5An exposure of sensitive system information to an unauthorized control sphere vulnerability has been reported to affect ...
CVE-2025-67269HIGH7.5An integer underflow vulnerability exists in the `nextstate()` function in `gpsd/packet.c` of gpsd versions prior to com...
CVE-2025-62842HIGH7.8An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attac...
CVE-2025-59387HIGH8.1An SQL injection vulnerability has been reported to affect MARS (Multi-Application Recovery Service). The remote attacke...
CVE-2025-59384HIGH7.5A path traversal vulnerability has been reported to affect Qfiling. The remote attackers can then exploit the vulnerabil...
CVE-2025-52872HIGH8.1A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker...
CVE-2025-52864HIGH8.1A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker...
CVE-2025-52863HIGH8.1A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker...
CVE-2025-15438HIGH7.2A vulnerability was determined in PluXml up to 5.8.22. Affected is the function FileCookieJar::__destruct of the file co...
CVE-2025-15432HIGH7.5A vulnerability has been found in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3. This vulnerability af...
CVE-2025-15431HIGH8.8A flaw has been found in UTT 进取 512W 1.7.7-171114. This affects the function strcpy of the file /goform/formFtpServerDir...
CVE-2025-15430HIGH8.8A vulnerability was detected in UTT 进取 512W 1.7.7-171114. Affected by this issue is the function strcpy of the file /gof...
CVE-2025-15429HIGH8.8A security vulnerability has been detected in UTT 进取 512W 1.7.7-171114. Affected by this vulnerability is the function s...
CVE-2025-15428HIGH8.8A weakness has been identified in UTT 进取 512W 1.7.7-171114. Affected is the function strcpy of the file /goform/formRemo...
CVE-2025-15426HIGH7.3A vulnerability was identified in jackying H-ui.admin up to 3.1. This affects an unknown function in the library /lib/we...
CVE-2025-15423HIGH8.8A vulnerability has been found in EmpireSoft EmpireCMS up to 8.0. Impacted is the function CheckSaveTranFiletype of the ...
CVE-2025-15422HIGH7.5A flaw has been found in EmpireSoft EmpireCMS up to 8.0. This issue affects the function egetip of the file e/class/conn...
CVE-2025-15413HIGH7.8A vulnerability was detected in wasm3 up to 0.5.0. Impacted is the function op_SetSlot_i32/op_CallIndirect of the file m...
CVE-2025-15412HIGH7.8A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decom...
CVE-2025-15411HIGH7.8A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::Inse...
CVE-2025-69203HIGH8.8Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the access req...
CVE-2025-68619HIGH7.2Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the appstore i...
CVE-2025-55065HIGH7.5CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now