2025 CVE Vulnerabilities

45,279 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-0138LOW2Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not expire when users are delet...
CVE-2025-0137MEDIUM4.8An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® softwar...
CVE-2025-0136MEDIUM5.3Using the AES-128-CCM algorithm for IPSec on certain Palo Alto Networks PAN-OS® firewalls (PA-7500, PA-5400, PA-5400f, P...
CVE-2025-0135LOW3.3An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a ...
CVE-2025-0134MEDIUM6.5A code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute a...
CVE-2025-0133LOW2.7A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal features of Palo Alto Netw...
CVE-2025-0132MEDIUM6.9A missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an unauthenticated user to dis...
CVE-2025-0131HIGH7.1An incorrect privilege management vulnerability in the OPSWAT MetaDefender Endpoint Security SDK used by the Palo Alto N...
CVE-2025-4664MEDIUM4.3Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cro...
CVE-2025-4639HIGH8.8CWE-611 Improper Restriction of XML External Entity Reference in the getDocumentBuilder() method of WebDav servlet in Pe...
CVE-2025-4638CRITICAL9.8A vulnerability exists in the inftrees.c component of the zlib library, which is bundled within the PointCloudLibrary (P...
CVE-2025-4637HIGH8.7Divide By Zero vulnerability in davisking dlib allows remote attackers to cause a denial of service via a crafted file...
CVE-2025-46786MEDIUM6.1Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network acc...
CVE-2025-46785MEDIUM6.5Buffer over-read in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service ...
CVE-2025-30668MEDIUM6.5Integer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct a denial of service via network...
CVE-2025-30667MEDIUM6.5NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of ...
CVE-2025-30666MEDIUM6.5NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of ...
CVE-2025-30665MEDIUM6.5NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of ...
CVE-2025-30664HIGH8.2Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege v...
CVE-2025-30663HIGH7Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escal...
CVE-2025-0130HIGH7.5A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenti...
CVE-2025-47710HIGH7.4Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows ...
CVE-2025-47709MEDIUM6.5Missing Authorization vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Forceful Browsing.This issue affect...
CVE-2025-47708HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Cross Site Request Forg...
CVE-2025-47707HIGH7.5Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now