2025 CVE Vulnerabilities

45,277 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-49164MEDIUM4.3Arris VIP1113 devices through 2025-05-30 with KreaTV SDK have a firmware decryption key of cd1c2d78f2cba1f73ca7e697b4a48...
CVE-2025-49163MEDIUM6.7Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow booting an arbitrary image via a crafted /usr/bin/gunzip ...
CVE-2025-49162MEDIUM6.4Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow file overwrite via TFTP because a remote filename with a ...
CVE-2025-3919MEDIUM6.4The WordPress Comments Import & Export plugin for WordPress is vulnerable to unauthorized modification of data due to a ...
CVE-2025-48996MEDIUM5.3HAX open-apis provides microservice apis for HAX webcomponents repo that are shared infrastructure calls. An unauthentic...
CVE-2025-48387HIGH8.7tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.0.9, 2.1.3, and 1.16.5 have an issue where an ex...
CVE-2025-47585MEDIUM6.5Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocomme...
CVE-2025-49069MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in cimatti Contact Forms by Cimatti contact-forms allows Cross Site Requ...
CVE-2025-23105HIGH7.8An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processo...
CVE-2025-23099CRITICAL9.1An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bou...
CVE-2025-1051HIGH8.8Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent...
CVE-2025-5086CRITICAL9A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could l...
CVE-2025-45387MEDIUM5.4osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php.
CVE-2025-27956HIGH7.5Directory Traversal vulnerability in WebLaudos 24.2 (04) allows a remote attacker to obtain sensitive information via th...
CVE-2025-27955MEDIUM6.5Clinical Collaboration Platform 12.2.1.5 has a weak logout system where the session token remains valid after logout and...
CVE-2025-27954MEDIUM6.5An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execut...
CVE-2025-27953MEDIUM6.5An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execut...
CVE-2025-23104MEDIUM6.5An issue was discovered in Samsung Mobile Processor Exynos 2200. A Use-After-Free in the mobile processor leads to privi...
CVE-2025-20298HIGH8In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to...
CVE-2025-20297MEDIUM5.4In Splunk Enterprise versions below 9.4.2, 9.3.4 and 9.2.6, and Splunk Cloud Platform versions below 9.3.2411.102, 9.3.2...
CVE-2025-5036HIGH7.8A maliciously crafted RFA file, when linked or imported into Autodesk Revit, can force a Use-After-Free vulnerability. A...
CVE-2025-48995MEDIUM6.9SignXML is an implementation of the W3C XML Signature standard in Python. When verifying signatures with X509 certificat...
CVE-2025-48994MEDIUM6.9SignXML is an implementation of the W3C XML Signature standard in Python. When verifying signatures with X509 certificat...
CVE-2025-48941MEDIUM5.3MyBB is free and open source forum software. Prior to version 1.8.39, the search component does not validate permissions...
CVE-2025-48940HIGH7.2MyBB is free and open source forum software. Prior to version 1.8.39, the upgrade component does not validate user input...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now