2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-70029HIGH7.5An issue in Sunbird-Ed SunbirdEd-portal v1.13.4 allows attackers to obtain sensitive information. The application disabl...
CVE-2025-69874CRITICAL9.8nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers t...
CVE-2025-65480HIGH8.8An issue was discovered in Pacom Unison Client 5.13.1. Authenticated users can inject malicious scripts in the Report Te...
CVE-2025-65128HIGH8.1A missing authentication mechanism in the web management API components of Shenzhen Zhibotong Electronics ZBT WE2001 23....
CVE-2025-65127MEDIUM6.5A lack of session validation in the web API component of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remot...
CVE-2025-13391MEDIUM5.8The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnerabl...
CVE-2025-64075CRITICAL10A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows ...
CVE-2025-12474MEDIUM4.4A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory. This ...
CVE-2025-61969HIGH7Incorrect permission assignment in AMD µProf may allow a local user-privileged attacker to achieve privilege escalation,...
CVE-2025-52541HIGH7.3A DLL hijacking vulnerability in Vivado could allow a local attacker to achieve privilege escalation, potentially result...
CVE-2025-48518MEDIUM6.9Improper input validation in AMD Graphics Driver could allow a local attacker to write out of bounds, potentially result...
CVE-2025-48508MEDIUM6Improper Hardware reset flow logic in the GPU GFX Hardware IP block could allow a privileged attacker in a guest virtual...
CVE-2025-48503HIGH7.8A DLL hijacking vulnerability in the AMD Software Installer could allow an attacker to achieve privilege escalation pote...
CVE-2025-12059CRITICAL9.8Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Logo Software Industry ...
CVE-2025-8668CRITICAL9.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite So...
CVE-2025-8025CRITICAL9.8Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinos...
CVE-2025-68406MEDIUM6.5A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the...
CVE-2025-66278MEDIUM6.5A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, th...
CVE-2025-66277CRITICAL9.8A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers ...
CVE-2025-66274MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...
CVE-2025-62856MEDIUM4.4A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator ac...
CVE-2025-62855MEDIUM4.4A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator ac...
CVE-2025-62854MEDIUM6.5An uncontrolled resource consumption vulnerability has been reported to affect File Station 5. If a remote attacker gain...
CVE-2025-62853MEDIUM6.5A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, th...
CVE-2025-59386MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now