2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-2486HIGH8.8The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, p...
CVE-2025-13084HIGH7.6The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys. ...
CVE-2025-11461HIGH8.8Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user-controlled parameters int...
CVE-2025-46175HIGH7.5Ruoyi v4.8.0 is vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the au...
CVE-2025-56396HIGH8.8An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department havi...
CVE-2025-46174HIGH7.5Ruoyi v4.8.0 vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the reset...
CVE-2025-45311HIGH8.8Insecure permissions in fail2ban-client v0.11.2 allows attackers with limited sudo privileges to perform arbitrary opera...
CVE-2025-13601HIGH7.7A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_u...
CVE-2025-13735HIGH7.4Out-of-bounds Read vulnerability in ASR1903、ASR3901 in ASR Lapwing_Linux on Linux (nr_fw modules). This vulnerability is...
CVE-2025-9558HIGH7.6There is a potential OOB Write vulnerability in the gen_prov_start function in pb_adv.c. The full length of the received...
CVE-2025-9557HIGH7.6‭An out-of-bound write can lead to an arbitrary code execution. Even on devices with some form of memory protection, thi...
CVE-2025-12061HIGH8.6The TAX SERVICE Electronic HDM WordPress plugin before 1.2.1 does not authorization and CSRF checks in an AJAX action, a...
CVE-2025-64983HIGH8.6Smart Video Doorbell firmware versions prior to 2.01.078 contain an active debug code vulnerability that allows an attac...
CVE-2025-66269HIGH7.1The RupsMon and USBMate services in UPSilon 2000 run with SYSTEM privileges and contain unquoted service paths. This all...
CVE-2025-66020HIGH7.5Valibot helps validate data using a schema. In versions from 0.31.0 to 1.1.0, the EMOJI_REGEX used in the emoji action i...
CVE-2025-66264HIGH7.2The CMService.exe service runs with SYSTEM privileges and contains an unquoted service path. This allows a local attacke...
CVE-2025-66263HIGH7.5Unauthenticated Arbitrary File Read via Null Byte Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmi...
CVE-2025-66252HIGH7.5Infinite Loop Denial of Service via Failed File Deletion in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitte...
CVE-2025-65957HIGH8.8Core Bot Is an Open Source discord bot made for maple hospital servers. Prior to commit dffe050, the API keys (SUPABASE_...
CVE-2025-65952HIGH8.7Console is a network used to control Gorilla Tag mods' users and other users on the network. Prior to version 2.8.0, a p...
CVE-2025-64713HIGH7.4WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, an out-...
CVE-2025-62703HIGH8.8Fugue is a unified interface for distributed computing that lets users execute Python, Pandas, and SQL code on Spark, Da...
CVE-2025-51741HIGH7.5An issue was discovered in Veal98 Echo Open-Source Community System 2.2 thru 2.3 allowing an unauthenticated attacker to...
CVE-2025-9624HIGH7.5A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string input...
CVE-2025-66017HIGH8.2CGGMP24 is a state-of-art ECDSA TSS protocol that supports 1-round signing (requires 3 preprocessing rounds), identifiab...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now