2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-10888HIGH7.8AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulne...
CVE-2025-10887HIGH7.8A maliciously crafted MODEL file, when parsed through certain Autodesk products, can force a Memory corruption vulnerabi...
CVE-2025-10886HIGH7.8A maliciously crafted MODEL file, when parsed through certain Autodesk products, can force a Memory corruption vulnerabi...
CVE-2025-10884HIGH7.8AA maliciously crafted CATPART file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vul...
CVE-2025-10883HIGH7.8A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read v...
CVE-2025-10882HIGH7.8AA maliciously crafted X_T file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnera...
CVE-2025-10881HIGH7.8A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vu...
CVE-2025-9121HIGH8.8Pentaho Data Integration and Analytics Community Dashboard Editor plugin versions before 10.2.0.4, including 9.3.0.x and...
CVE-2025-14730HIGH7.2A security flaw has been discovered in CTCMS Content Management System up to 2.1.2. The impacted element is an unknown f...
CVE-2025-14729HIGH7.2A vulnerability was identified in CTCMS Content Management System up to 2.1.2. The affected element is the function Save...
CVE-2025-14503HIGH8.6An overly-permissive IAM trust policy in the Harmonix on AWS framework may allow IAM principals in the same AWS account ...
CVE-2025-65176HIGH7.5An issue was discovered in Dynatrace OneAgent before 1.325.47. When attempting to access a remote network share from a m...
CVE-2025-66440HIGH8.8An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext/acc...
CVE-2025-66439HIGH8.8An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext.acc...
CVE-2025-66438HIGH8.8A Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNext through 15.89.0 Print Format renderin...
CVE-2025-66437HIGH8.8An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext throug...
CVE-2025-14038HIGH7EDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints. Th...
CVE-2025-66434HIGH8.8An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning_letter_text method of Frappe ERPNext th...
CVE-2025-65742HIGH8.2An unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11.0 allows attackers to...
CVE-2025-11393HIGH8.7A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of...
CVE-2025-60786HIGH8.8A Zip Slip vulnerability in the import a Project component of iceScrum v7.54 Pro On-prem allows attackers to execute arb...
CVE-2025-13824HIGH8.7A security issue exists due to improper handling of malformed CIP packets during fuzzing. The controller enters a hard f...
CVE-2025-13823HIGH7.1A security issue was found in the IPv6 stack in the Micro850 and Micro870 controllers when the controllers received mult...
CVE-2025-34181HIGH8.7NetSupport Manager < 14.12.0001 contains an arbitrary file write vulnerability in its Connectivity Server/Gateway PUTFIL...
CVE-2025-34180HIGH8.4NetSupport Manager < 14.12.0001 relies on a shared Gateway Key for authentication between Manager/Control, Client, and ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now