2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-55590MEDIUM6.5TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an command injection vulnerability via the component bup...
CVE-2025-55589MEDIUM6.5TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain multiple OS command injection vulnerabilities via the ma...
CVE-2025-55588HIGH7.5TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the fw_ip parameter at /boafrm/form...
CVE-2025-55587HIGH7.5TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the hostname parameter at /boafrm/f...
CVE-2025-55586HIGH7.5TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the url parameter at /boafrm/formFi...
CVE-2025-55585MEDIUM6.5TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an eval injection vulnerability via the eval() function.
CVE-2025-55584MEDIUM5.3TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain insecure credentials for the telnet service and root acc...
CVE-2025-55213CRITICAL9.8OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z...
CVE-2025-53192HIGH8.8** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons...
CVE-2025-4371HIGH7A potential vulnerability was reported in the Lenovo 510 FHD and Performance FHD web cameras that could allow an attacke...
CVE-2025-32992HIGH8.5Thermo Fisher Scientific ePort through 3.0.0 has Incorrect Access Control.
CVE-2025-43731MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025...
CVE-2025-7693CRITICAL9.3A security issue exists due to improper handling of malformed CIP Forward Close packets during fuzzing. The controller e...
CVE-2025-55300HIGH8.6Komari is a lightweight, self-hosted server monitoring tool designed to provide a simple and efficient solution for moni...
CVE-2025-55299CRITICAL9.4VaulTLS is a modern solution for managing mTLS (mutual TLS) certificates. Prior to 0.9.1, user accounts created through ...
CVE-2025-55296MEDIUM5.4librenms is a community-based GPL-licensed network monitoring system. A stored Cross-Site Scripting (XSS) vulnerability ...
CVE-2025-55293CRITICAL9.8Meshtastic is an open source mesh networking solution. Prior to v2.6.3, an attacker can send NodeInfo with a empty publi...
CVE-2025-55291HIGH7.1Shaarli is a minimalist bookmark manager and link sharing service. Prior to 0.15.0, the input string in the cloud tag pa...
CVE-2025-55288MEDIUM5.4Genealogy is a family tree PHP application. Prior to 4.4.0, Authenticated Reflected Cross-Site Scripting (XSS) vulnerabi...
CVE-2025-55287MEDIUM5.4Genealogy is a family tree PHP application. Prior to 4.4.0, Authenticated Stored Cross-Site Scripting (XSS) vulnerabilit...
CVE-2025-55283HIGH7.2aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that...
CVE-2025-55282HIGH7.2aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that...
CVE-2025-55214MEDIUM6.9Copier library and CLI app for rendering project templates. From 7.1.0 to before 9.9.1, Copier suggests that it's safe t...
CVE-2025-55205CRITICAL9Capsule is a multi-tenancy and policy-based framework for Kubernetes. A namespace label injection vulnerability in Capsu...
CVE-2025-55201HIGH8.5Copier library and CLI app for rendering project templates. Prior to 9.9.1, a safe template can currently read and write...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now