2025 CVE Vulnerabilities

45,277 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-23247HIGH7.8NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a failure to check the len...
CVE-2025-22377MEDIUM6.5An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128...
CVE-2025-5248CRITICAL9.8A vulnerability, which was classified as critical, was found in PHPGurukul Company Visitor Management System 1.0. Affect...
CVE-2025-48370LOW2.7auth-js is an isomorphic Javascript library for Supabase Auth. Prior to version 2.70.0, the library functions getUserByI...
CVE-2025-27701MEDIUM5.5In the function process_crypto_cmd, the values of ptrs[i] can be potentially equal to NULL which is valid value after ca...
CVE-2025-27700HIGH8.4There is a possible bypass of carrier restrictions due to an unusual root cause. This could lead to local escalation of ...
CVE-2025-5247HIGH7.3A vulnerability, which was classified as critical, has been found in Gowabby HFish 0.1. This issue affects the function ...
CVE-2025-5246CRITICAL9.8A vulnerability classified as critical was found in Campcodes Online Hospital Management System 1.0. This vulnerability ...
CVE-2025-5245HIGH7.8A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_s...
CVE-2025-48383HIGH8.2Django-Select2 is a Django integration for Select2. Prior to version 8.4.1, instances of HeavySelect2Mixin subclasses li...
CVE-2025-3704MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DBAR Productions V...
CVE-2025-2236LOW2.1Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in OpenText Advanced Authentica...
CVE-2025-48798HIGH7.3A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been special...
CVE-2025-48797HIGH7.3A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been...
CVE-2025-48796HIGH7.3A flaw was found in GIMP. The GIMP ani_load_image() function is vulnerable to a stack-based overflow. If a user opens.AN...
CVE-2025-5272HIGH7.3Memory safety bugs present in Firefox 138 and Thunderbird 138. Some of these bugs showed evidence of memory corruption a...
CVE-2025-5271MEDIUM6.5Previewing a response in Devtools ignored CSP headers, which could have allowed content injection attacks. This vulnerab...
CVE-2025-5270HIGH7.5In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability was fixed...
CVE-2025-5269HIGH8.1Memory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of memory corruption a...
CVE-2025-5268HIGH8.1Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10. Some of these bu...
CVE-2025-5267MEDIUM5.4A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious...
CVE-2025-5266MEDIUM4.3Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leak...
CVE-2025-5265MEDIUM4.8Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user in...
CVE-2025-5264MEDIUM4.8Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into...
CVE-2025-5263MEDIUM4.3Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin lea...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now