2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-65203HIGH7.1KeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-e...
CVE-2025-67285HIGH7.3A SQL injection vulnerability was found in the '/cts/admin/?page=zone' file of ITSourcecode COVID Tracking System Using ...
CVE-2025-66921HIGH7.2A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows re...
CVE-2025-53919HIGH7.8An issue was discovered in the Portrait Dell Color Management application through 3.3.008 for Dell monitors, It creates ...
CVE-2025-53398HIGH7.8The Portrait Dell Color Management application 3.3.8 for Dell monitors has Insecure Permissions,
CVE-2025-43873HIGH8.7Successful exploitation of these vulnerabilities could allow an attacker to modify firmware and gain full access to the ...
CVE-2025-14727HIGH8.7A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation. Note: Software v...
CVE-2025-61736HIGH7.1Successful exploitation of this vulnerability could result in the product failing to re-establish communication once the...
CVE-2025-14097HIGH7.2A vulnerability in the application software of multiple Radiometer products may allow remote code execution and unauthor...
CVE-2025-14096HIGH8.4A vulnerability exists in multiple Radiometer products that allow an attacker with physical access to the analyzer possi...
CVE-2025-14101HIGH7.1Authorization Bypass Through User-Controlled Key vulnerability in GG Soft Software Services Inc. PaperWork allows Exploi...
CVE-2025-11924HIGH7.5The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Insecure Direct Obj...
CVE-2025-11901HIGH7An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760...
CVE-2025-14305HIGH8.5ListCheck.exe developed by Acer has a Local Privilege Escalation vulnerability. Authenticated local attackers can replac...
CVE-2025-14303HIGH7Certain motherboard models developed by MSI has a Protection Mechanism Failure vulnerability. Because IOMMU was not prop...
CVE-2025-53524HIGH8.4Fuji Electric Monitouch V-SFT-6 is vulnerable to an out-of-bounds write while processing a specially crafted project fi...
CVE-2025-14701HIGH7.1An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated...
CVE-2025-14766HIGH8.8Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exp...
CVE-2025-14765HIGH8.8Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap ...
CVE-2025-68274HIGH7.5SIPGO is a library for writing SIP services in the GO language. Starting in version 0.3.0 and prior to version 1.0.0-alp...
CVE-2025-52582HIGH7.5An out-of-bounds read vulnerability exists in the Overlay::GrabOverlayFromPixelData functionality of Grassroot DICOM 3.0...
CVE-2025-8872HIGH7.1On affected platforms running Arista EOS with OSPFv3 configured, a specially crafted packet can cause the OSFPv3 process...
CVE-2025-68156HIGH7.5Expr is an expression language and expression evaluation for Go. Prior to version 1.17.7, several builtin functions in E...
CVE-2025-68155HIGH7.5@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_find...
CVE-2025-68154HIGH8.1systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` funct...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now