2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-15218HIGH8.8A weakness has been identified in Tenda AC10U 15.03.06.48/15.03.06.49. Affected by this vulnerability is the function fr...
CVE-2025-15217HIGH8.8A security flaw has been discovered in Tenda AC23 16.03.07.52. Affected is the function formSetPPTPUserList of the compo...
CVE-2025-15216HIGH8.8A vulnerability was identified in Tenda AC23 16.03.07.52. This impacts the function fromSetIpMacBind of the file /goform...
CVE-2025-15215HIGH8.8A vulnerability was determined in Tenda AC10U 15.03.06.48/15.03.06.49. This affects the function formSetPPTPUserList of ...
CVE-2025-69235HIGH7.5Whale browser before 4.35.351.12 allows an attacker to bypass the Same-Origin Policy in a sidebar environment.
CVE-2025-69217HIGH7.7coturn is a free open source implementation of TURN and STUN Server. Versions 4.6.2r5 through 4.7.0-r4 have a bad random...
CVE-2025-68036HIGH7.5Missing Authorization vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Accessing Functionality Not Properly...
CVE-2025-23554HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jakub Glos Off Pag...
CVE-2025-23550HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kemal YAZICI Produ...
CVE-2025-23469HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sleekplan Sleekpla...
CVE-2025-23458HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rakessh Ads24 Lite...
CVE-2025-15205HIGH8.8A vulnerability was identified in code-projects Student File Management System 1.0. Affected by this vulnerability is an...
CVE-2025-68431HIGH7.1libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the ...
CVE-2025-67255HIGH8.8In NagiosXI 2026R1.0.1 build 1762361101, Dashboard parameters lack proper filtering, allowing any authenticated user to ...
CVE-2025-67254HIGH7.5NagiosXI 2026R1.0.1 build 1762361101 is vulnerable to Directory Traversal in /admin/coreconfigsnapshots.php.
CVE-2025-15199HIGH8.8A security vulnerability has been detected in code-projects College Notes Uploading System 1.0. Impacted is an unknown f...
CVE-2025-13592HIGH7.2The Advanced Ads plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.0.14 vi...
CVE-2025-68861HIGH7.1Missing Authorization vulnerability in pluginoptimizer Plugin Optimizer plugin-optimizer allows Exploiting Incorrectly C...
CVE-2025-66877HIGH7.5Buffer overflow vulnerability in function dcputchar in decompile.c in libming 0.4.8.
CVE-2025-55061HIGH8.8CWE-434 Unrestricted Upload of File with Dangerous Type
CVE-2025-68870HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-66869HIGH7.5Buffer overflow vulnerability in function strcat in asan_interceptors.cpp in libming 0.4.8.
CVE-2025-66866HIGH7.5An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial...
CVE-2025-66865HIGH7.5An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause ...
CVE-2025-66864HIGH7.5An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now