2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-54306HIGH7.2An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. A remote code execution vulnerabil...
CVE-2025-54305HIGH7.8An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. One of the middlewares included in...
CVE-2025-40216HIGH7.8In the Linux kernel, the following vulnerability has been resolved: io_uring/rsrc: don't rely on user vaddr alignment ...
CVE-2025-29846HIGH7.2A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages.
CVE-2025-14008HIGH7.2A flaw has been found in dayrui XunRuiCMS up to 4.7.1. This vulnerability affects unknown code of the file admin79f2ec22...
CVE-2025-40215HIGH7.8In the Linux kernel, the following vulnerability has been resolved: xfrm: delete x->tunnel as we delete x The ipcomp f...
CVE-2025-40214HIGH7.8In the Linux kernel, the following vulnerability has been resolved: af_unix: Initialise scc_index in unix_add_edge(). ...
CVE-2025-11727HIGH7.2The Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration – Powered by Codisto plugin for WordPress is...
CVE-2025-62173HIGH8.6## Summary Authenticated SQL Injection Vulnerability in Endpoint Module Rest API
CVE-2025-66404HIGH8.8MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. Prior to 2.9.8, there is ...
CVE-2025-66293HIGH7.1LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ...
CVE-2025-65868HIGH7.5XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted b...
CVE-2025-66453HIGH7.5Rhino is an open-source implementation of JavaScript written entirely in Java. Prior to 1.8.1, 1.7.15.1, and 1.7.14.1, w...
CVE-2025-65027HIGH7.6RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive inte...
CVE-2025-13086HIGH7.5Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows...
CVE-2025-12385HIGH8.7Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability i...
CVE-2025-66220HIGH7.1Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, Envoy’s mTLS ce...
CVE-2025-50360HIGH8.4A heap buffer overflow in compiler.c and compiler.h in Pepper language 0.1.1commit 961a5d9988c5986d563310275adad3fd181b2...
CVE-2025-33211HIGH7.5NVIDIA Triton Server for Linux contains a vulnerability where an attacker may cause an improper validation of specified ...
CVE-2025-33208HIGH8.8NVIDIA TAO contains a vulnerability where an attacker may cause a resource to be loaded via an uncontrolled search path....
CVE-2025-33201HIGH7.5NVIDIA Triton Inference Server contains a vulnerability where an attacker may cause an improper check for unusual or exc...
CVE-2025-12819HIGH8.1Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to ...
CVE-2025-66431HIGH7.8WebPros Plesk before 18.0.73.5 and 18.0.74 before 18.0.74.2 on Linux allows remote authenticated users to execute arbitr...
CVE-2025-65843HIGH7.7Aquarius Desktop 3.0.069 for macOS contains an insecure file handling vulnerability in its support data archive generati...
CVE-2025-54326HIGH7.5An issue was discovered in Camera in Samsung Mobile Processor Exynos 1280 and 2200. Unnecessary registration of a hardwa...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now