2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-9558HIGH7.6There is a potential OOB Write vulnerability in the gen_prov_start function in pb_adv.c. The full length of the received...
CVE-2025-9557HIGH7.6‭An out-of-bound write can lead to an arbitrary code execution. Even on devices with some form of memory protection, thi...
CVE-2025-12061HIGH8.6The TAX SERVICE Electronic HDM WordPress plugin before 1.2.1 does not authorization and CSRF checks in an AJAX action, a...
CVE-2025-64983HIGH8.6Smart Video Doorbell firmware versions prior to 2.01.078 contain an active debug code vulnerability that allows an attac...
CVE-2025-66269HIGH7.1The RupsMon and USBMate services in UPSilon 2000 run with SYSTEM privileges and contain unquoted service paths. This all...
CVE-2025-66020HIGH7.5Valibot helps validate data using a schema. In versions from 0.31.0 to 1.1.0, the EMOJI_REGEX used in the emoji action i...
CVE-2025-66264HIGH7.2The CMService.exe service runs with SYSTEM privileges and contains an unquoted service path. This allows a local attacke...
CVE-2025-66263HIGH7.5Unauthenticated Arbitrary File Read via Null Byte Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmi...
CVE-2025-66252HIGH7.5Infinite Loop Denial of Service via Failed File Deletion in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitte...
CVE-2025-65957HIGH8.8Core Bot Is an Open Source discord bot made for maple hospital servers. Prior to commit dffe050, the API keys (SUPABASE_...
CVE-2025-65952HIGH8.7Console is a network used to control Gorilla Tag mods' users and other users on the network. Prior to version 2.8.0, a p...
CVE-2025-64713HIGH7.4WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, an out-...
CVE-2025-62703HIGH8.8Fugue is a unified interface for distributed computing that lets users execute Python, Pandas, and SQL code on Spark, Da...
CVE-2025-51741HIGH7.5An issue was discovered in Veal98 Echo Open-Source Community System 2.2 thru 2.3 allowing an unauthenticated attacker to...
CVE-2025-9624HIGH7.5A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string input...
CVE-2025-66017HIGH8.2CGGMP24 is a state-of-art ECDSA TSS protocol that supports 1-round signing (requires 3 preprocessing rounds), identifiab...
CVE-2025-65965HIGH8.2Grype is a vulnerability scanner for container images and filesystems. A credential disclosure vulnerability was found i...
CVE-2025-12816HIGH8.6An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated atta...
CVE-2025-64065HIGH8.8The Primakon Pi Portal 1.0.18 API /api/V2/pp_udfv_admin endpoint, fails to perform necessary server-side validation. The...
CVE-2025-64064HIGH8.8Primakon Pi Portal 1.0.18 /api/v2/pp_users endpoint fails to adequately check user permissions before processing a PATCH...
CVE-2025-34350HIGH8.7UnForm Server versions < 10.1.15 contain an unauthenticated arbitrary file read and SMB coercion vulnerability in the Do...
CVE-2025-64066HIGH8.6Primakon Pi Portal 1.0.18 REST /api/v2/user/register endpoint suffers from a Broken Access Control vulnerability. The en...
CVE-2025-64062HIGH8.8The Primakon Pi Portal 1.0.18 /api/V2/pp_users?email endpoint is used for user data filtering but lacks proper server-si...
CVE-2025-33205HIGH7.3NVIDIA NeMo framework contains a vulnerability in a predefined variable, where an attacker could cause inclusion of func...
CVE-2025-33204HIGH7.8NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP and LLM components, where malicious data cre...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now