2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-69421HIGH7.5Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i...
CVE-2025-69420HIGH7.5Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE unio...
CVE-2025-69419HIGH7.4Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16...
CVE-2025-69418MEDIUM4Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs...
CVE-2025-68670CRITICAL9.8xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerabi...
CVE-2025-68160MEDIUM4.7Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO perf...
CVE-2025-66199MEDIUM5.9Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decomp...
CVE-2025-55102HIGH7.5A denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A special...
CVE-2025-55095HIGH7The function _ux_host_class_storage_media_mount() is responsible for mounting partitions on a USB mass storage device. W...
CVE-2025-28164MEDIUM5.5Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_creat...
CVE-2025-28162MEDIUM5.5Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngim...
CVE-2025-15469MEDIUM5.5Issue summary: The 'openssl dgst' command-line tool silently truncates input data to 16MB when using one-shot signing al...
CVE-2025-15468MEDIUM5.9Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an un...
CVE-2025-15467HIGH8.8Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigg...
CVE-2025-11187MEDIUM6.1Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow...
CVE-2025-41728MEDIUM5.3A low privileged remote attacker may be able to disclose confidential information from the memory of a privileged proces...
CVE-2025-41727HIGH7.8A local low privileged attacker can bypass the authentication of the Device Manager user interface, allowing them to per...
CVE-2025-41726HIGH8.8A low privileged remote attacker can execute arbitrary code by sending specially crafted calls to the web service of the...
CVE-2025-12387MEDIUM6.9A vulnerability in the Pix-Link LV-WR21Q router's language module allows remote attackers to trigger a denial of service...
CVE-2025-12386MEDIUM6.9Pix-Link LV-WR21Q does not enforce any form of authentication for endpoint /goform/getHomePageInfo. Remote unauthenticat...
CVE-2025-14971MEDIUM5.3The Link Invoice Payment for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to ...
CVE-2025-30248HIGH8.9DLL hijacking in the WD Discovery Installer in Western Digital WD Discovery 5.2.730 on Windows allows a local attacker t...
CVE-2025-59473HIGH7.2SQL Injection vulnerability in the Structure for Admin authenticated user
CVE-2025-59472HIGH7.5A denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in min...
CVE-2025-59471HIGH7.5A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now