2025 CVE Vulnerabilities

45,267 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-49218HIGH7.8A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to e...
CVE-2025-49217CRITICAL9.8An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentica...
CVE-2025-49216CRITICAL9.8An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to ac...
CVE-2025-49215HIGH8.8A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to e...
CVE-2025-49214HIGH8.8An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a post-authentic...
CVE-2025-49213CRITICAL9.8An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentica...
CVE-2025-49212CRITICAL9.8An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentica...
CVE-2025-49211HIGH7.8A SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate pr...
CVE-2025-48443MEDIUM6.6Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Local Privilege E...
CVE-2025-41413HIGH8.4Fuji Electric Smart Editor is vulnerable to an out-of-bounds write, which may allow an attacker to execute arbitrary cod...
CVE-2025-41388HIGH8.4Fuji Electric Smart Editor is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitr...
CVE-2025-32412HIGH8.4Fuji Electric Smart Editor is vulnerable to an out-of-bounds read, which may allow an attacker to execute arbitrary code...
CVE-2025-30642MEDIUM5.5A link following vulnerability in Trend Micro Deep Security 20.0 agents could allow a local attacker to create a denial ...
CVE-2025-30641HIGH7.8A link following vulnerability in the anti-malware solution portion of Trend Micro Deep Security 20.0 agents could allow...
CVE-2025-30640HIGH7.8A link following vulnerability in Trend Micro Deep Security 20.0 agents could allow a local attacker to escalate privile...
CVE-2025-5141MEDIUM5.5A binary in the BoKS Server Agent component of Fortra's Core Privileged Access Manager (BoKS) on versions 7.2.0 (up to 7...
CVE-2025-49847HIGH8.8llama.cpp is an inference of several LLM models in C/C++. Prior to version b5662, an attacker‐supplied GGUF model vocabu...
CVE-2025-45526LOW2.9A denial of service (DoS) vulnerability has been identified in the JavaScript library microlight version 0.0.7. This lib...
CVE-2025-45525LOW2.9A NULL pointer dereference vulnerability has been identified in the JavaScript library microlight version 0.0.7, a light...
CVE-2025-30680HIGH7.1A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (SaaS) could allow an attacker to manipul...
CVE-2025-30679HIGH7.5A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modOSCE component could allo...
CVE-2025-30678HIGH7.5A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modTMSM component could allo...
CVE-2025-49850HIGH8.4A Heap-based Buffer Overflow vulnerability exists within the parsing of PRJ files. The issues result from the lack of pr...
CVE-2025-49849HIGH8.4An Out-of-bounds Read vulnerability exists within the parsing of PRJ files. The issues result from the lack of proper va...
CVE-2025-49848HIGH8.4An out-of-bounds write vulnerability exists within the parsing of PRJ files. The issues result from the lack of proper v...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now