2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-7675HIGH7.8A maliciously crafted 3DM file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerab...
CVE-2025-7497HIGH7.8A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerab...
CVE-2025-6637HIGH7.8A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerab...
CVE-2025-6636HIGH7.8A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability....
CVE-2025-6635HIGH7.8A maliciously crafted PRT file, when linked or imported into certain Autodesk products, can force an Out-of-Bounds Read ...
CVE-2025-6631HIGH7.8A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerab...
CVE-2025-5043HIGH7.8A maliciously crafted 3DM file, when linked or imported into certain Autodesk products, can force a Heap-Based Overflow ...
CVE-2025-5038HIGH7.8A maliciously crafted X_T file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerabili...
CVE-2025-53715HIGH7.5A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/Wan6to4TunnelCfgRpm.ht...
CVE-2025-53714HIGH7.5A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WzdWlanSiteSurveyRpm_A...
CVE-2025-53713HIGH7.5A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WlanNetworkRpm_APC.htm...
CVE-2025-53712HIGH7.5A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WlanNetworkRpm_AP.htm ...
CVE-2025-53711HIGH7.5A vulnerability has been found in TP-Link TL-WR841N v11, TL-WR842ND v2 and TL-WR494N v3. The vulnerability exists in the...
CVE-2025-52284MEDIUM6.5Totolink X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_4184C0 functio...
CVE-2025-36010HIGH7.5IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 could allow an unauthenticated user to cause a denial of service due to e...
CVE-2025-2928HIGH7.2SQL Injection affecting the Archiver role.
CVE-2025-2533HIGH7.5IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a denial of service as the server may crash under certain ...
CVE-2025-2179MEDIUM6.8An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on Linux devices enables a ...
CVE-2025-27514MEDIUM5.4GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an...
CVE-2025-5922MEDIUM4.8Access to TSplus Remote Access Admin Tool is restricted to administrators (unless "Disable UAC" option is enabled) and r...
CVE-2025-54432Rejected reason: This CVE is a duplicate of another CVE. See CVE-2018-25031 and CVE-2021-46708.
CVE-2025-54420Rejected reason: This CVE is a duplicate of CVE-2025-8129.
CVE-2025-44137HIGH8.2MapTiler Tileserver-php v2.0 is vulnerable to Directory Traversal. The renderTile function within tileserver.php is resp...
CVE-2025-44136CRITICAL9.8MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an e...
CVE-2025-31965HIGH8.2Improper access restrictions in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0248 and lower) allow non-admin ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now