2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-58468HIGH8.8A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers ...
CVE-2025-71319HIGH8.7image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block th...
CVE-2025-55657HIGH7.5A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descriptors.c) of GPAC MP4Box v2.4 allows attack...
CVE-2025-52293HIGH7.5A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allo...
CVE-2025-52292HIGH7.5A stack buffer overflow in the filein_process function (in_file.c) of GPAC MP4Box v2.4 allows attackers to cause a Denia...
CVE-2025-5090HIGH7.1CVX is not resilient to unexpected messages from a connected switch. This leads to agent crashes on CVX causing instabil...
CVE-2025-5089HIGH7.1In a CVX cluster, an EOS switch connected to a CVX server is not resilient to certain malformed messages received from t...
CVE-2025-5088HIGH8.7An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. Note that thi...
CVE-2025-59174HIGH7.1Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large v...
CVE-2025-8873HIGH8.7On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane to st...
CVE-2025-69755HIGH8.2An issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a remote attacker to obtain sensitive information and ...
CVE-2025-67448HIGH7.1The SMS module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to stored XSS. The application does not...
CVE-2025-59874HIGH8.1HCL Hive Telco Observability is affected by  a Required directives missing from the CSP issue is detected in keycloak co...
CVE-2025-46638HIGH7.5Dell BSAFE SSL-J contains an allocation of resources without limits or throttling vulnerability. An unauthenticated remo...
CVE-2025-52612HIGH8.8HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site script...
CVE-2025-12694HIGH7.8A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user t...
CVE-2025-41259HIGH7.3SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivilege...
CVE-2025-15656HIGH8.8Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. This issue affe...
CVE-2025-15655HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla School Ma...
CVE-2025-14774HIGH7.4Incorrect Authorization vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.
CVE-2025-14772HIGH8.8Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24...
CVE-2025-15654HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fox-themes Prague ...
CVE-2025-15653HIGH7Dräger Zeus Infinity Empowered (Zeus IE) and Zeus RS C500 anesthesia workstations contain a local security vulnerability...
CVE-2025-64390HIGH7.4A privilege escalation vulnerability exists in PlayStation 4 firmware versions 13.00 through 13.02. The BD-J (Blu-ray Di...
CVE-2025-69369HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now