2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-62850HIGH7.2A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...
CVE-2025-58468HIGH8.8A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers ...
CVE-2025-71319HIGH8.7image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block th...
CVE-2025-55657HIGH7.5A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descriptors.c) of GPAC MP4Box v2.4 allows attack...
CVE-2025-52293HIGH7.5A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allo...
CVE-2025-52292HIGH7.5A stack buffer overflow in the filein_process function (in_file.c) of GPAC MP4Box v2.4 allows attackers to cause a Denia...
CVE-2025-5090HIGH7.1CVX is not resilient to unexpected messages from a connected switch. This leads to agent crashes on CVX causing instabil...
CVE-2025-5089HIGH7.1In a CVX cluster, an EOS switch connected to a CVX server is not resilient to certain malformed messages received from t...
CVE-2025-5088HIGH8.7An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. Note that thi...
CVE-2025-59174HIGH7.1Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large v...
CVE-2025-8873HIGH8.7On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane to st...
CVE-2025-69755HIGH8.2An issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a remote attacker to obtain sensitive information and ...
CVE-2025-67448HIGH7.1The SMS module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to stored XSS. The application does not...
CVE-2025-59874HIGH8.1HCL Hive Telco Observability is affected by  a Required directives missing from the CSP issue is detected in keycloak co...
CVE-2025-46638HIGH7.5Dell BSAFE SSL-J contains an allocation of resources without limits or throttling vulnerability. An unauthenticated remo...
CVE-2025-52612HIGH8.8HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site script...
CVE-2025-12694HIGH7.8A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user t...
CVE-2025-41259HIGH7.3SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivilege...
CVE-2025-15656HIGH8.8Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. This issue affe...
CVE-2025-15655HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla School Ma...
CVE-2025-14774HIGH7.4Incorrect Authorization vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.
CVE-2025-14772HIGH8.8Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24...
CVE-2025-15654HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fox-themes Prague ...
CVE-2025-15653HIGH7Dräger Zeus Infinity Empowered (Zeus IE) and Zeus RS C500 anesthesia workstations contain a local security vulnerability...
CVE-2025-64390HIGH7.4A privilege escalation vulnerability exists in PlayStation 4 firmware versions 13.00 through 13.02. The BD-J (Blu-ray Di...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now