2025 CVE Vulnerabilities

45,279 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-4574MEDIUM6.5In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some c...
CVE-2025-47905MEDIUM5.4Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via H...
CVE-2025-26646HIGH8External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized att...
CVE-2025-4668Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2025-43572HIGH7.8Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary...
CVE-2025-43571HIGH7.8Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbi...
CVE-2025-43570HIGH7.8Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbi...
CVE-2025-43569HIGH7.8Substance3D - Stager versions 3.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result i...
CVE-2025-43568HIGH7.8Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbi...
CVE-2025-43567CRITICAL9.3Adobe Connect versions 12.8 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability that could ...
CVE-2025-43566MEDIUM6.8ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Limitation of a Pathname to a Restr...
CVE-2025-43565HIGH8.4ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that c...
CVE-2025-43564CRITICAL9.1ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that c...
CVE-2025-43563CRITICAL9.1ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that c...
CVE-2025-43562CRITICAL9.1ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements ...
CVE-2025-43561CRITICAL9.1ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that c...
CVE-2025-43560CRITICAL9.1ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that...
CVE-2025-43559CRITICAL9.1ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that...
CVE-2025-43554HIGH7.8Substance3D - Modeler versions 1.21.0 and earlier are affected by an out-of-bounds write vulnerability that could result...
CVE-2025-43553HIGH7.8Substance3D - Modeler versions 1.21.0 and earlier are affected by an Uncontrolled Search Path Element vulnerability that...
CVE-2025-43551MEDIUM5.5Substance3D - Stager versions 3.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to d...
CVE-2025-43549HIGH7.8Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbi...
CVE-2025-43548HIGH7.8Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary...
CVE-2025-30316MEDIUM5.4Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be ...
CVE-2025-30315MEDIUM6.1Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now