2025 CVE Vulnerabilities

45,266 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-23264HIGH7.8NVIDIA Megatron-LM for all platforms contains a vulnerability in a python component where an attacker may cause a code i...
CVE-2025-6569MEDIUM6.1A vulnerability classified as problematic was found in code-projects School Fees Payment System 1.0. Affected by this vu...
CVE-2025-6568HIGH8.8A vulnerability classified as critical has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is an unknown...
CVE-2025-6567CRITICAL9.8A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been rated as critical. This iss...
CVE-2025-36537HIGH7Incorrect Permission Assignment for Critical Resource in the TeamViewer Client (Full and Host) of TeamViewer Remote and ...
CVE-2025-32978HIGH7.5Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14....
CVE-2025-32977CRITICAL9.6Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14....
CVE-2025-32976HIGH8.8Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14....
CVE-2025-32975CRITICAL10Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14....
CVE-2025-6032HIGH8.3A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM ...
CVE-2025-5318MEDIUM5.4A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_...
CVE-2025-27828HIGH7.1A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4, 10.1.0.0 through 10.1....
CVE-2025-27827HIGH7.1A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.2.0.3 could allow an unauthen...
CVE-2025-6566HIGH7.5A vulnerability was found in oatpp Oat++ up to 1.3.1. It has been declared as critical. This vulnerability affects the f...
CVE-2025-6565HIGH8.8A vulnerability was found in Netgear WNCE3001 1.0.0.50. It has been classified as critical. This affects the function ht...
CVE-2025-6436HIGH8.1Memory safety bugs present in Firefox 139 and Thunderbird 139. Some of these bugs showed evidence of memory corruption a...
CVE-2025-6435HIGH8.1If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not hav...
CVE-2025-6434MEDIUM4.3The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking ...
CVE-2025-6433CRITICAL9.8If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a...
CVE-2025-6432HIGH8.6When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was inval...
CVE-2025-6431MEDIUM6.5When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing...
CVE-2025-6430MEDIUM6.1When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was ...
CVE-2025-6429MEDIUM6.5Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in...
CVE-2025-6428MEDIUM4.3When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correc...
CVE-2025-6427CRITICAL9.1An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. Th...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now