2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-26483HIGH8.2Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticated attacker c...
CVE-2025-71217HIGH7.8An origin validation error vulnerability in the Trend Micro Apex One (mac) agent self-protection mechanism could allow a...
CVE-2025-71216HIGH7.8A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent cache mechanism could allow a local at...
CVE-2025-71215HIGH7A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent iCore service signature verification c...
CVE-2025-71214HIGH7.8An origin validation error vulnerability in the Trend Micro Apex One (mac) agent iCore service could allow a local attac...
CVE-2025-71213HIGH7.8An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on ...
CVE-2025-71212HIGH7.8A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalate privileg...
CVE-2025-13479HIGH7.5Authorization bypass through User-Controlled key vulnerability in PosCube Hardware Software and Consulting Ltd. QR Menu ...
CVE-2025-13477HIGH7.1Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerability in...
CVE-2025-32750HIGH7.5Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerabilit...
CVE-2025-11954HIGH8Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd. Co. WISECP allows Cross S...
CVE-2025-70950HIGH7.3An issue in gohttp commit 34ea51 allows attackers to execute a directory traversal via supplying a crafted request.
CVE-2025-51427HIGH7.3An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in t...
CVE-2025-15609HIGH7.5The Fortis for WooCommerce WordPress plugin before 1.3.1 may leak sensitive API keys to unauthenticated attackers, allow...
CVE-2025-57282HIGH8.8ngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection.
CVE-2025-56352HIGH7.5In tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), the broker mishandles protocol violations duri...
CVE-2025-54518HIGH7.3Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to...
CVE-2025-54517HIGH8.5Out of bounds write in AMD AMDGV_CMD_GET_DIAG_DATA ioctl handler could allow a local user to escalate privileges via rem...
CVE-2025-29938HIGH7.1An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to write to an arbi...
CVE-2025-29936HIGH8.4Improper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary ...
CVE-2025-29935HIGH8.4An out of bounds write within the AMD Platform Management Framework (PMF) could allow an attacker to execute arbitrary c...
CVE-2025-0028HIGH8.3An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify ...
CVE-2025-52540HIGH8.5An improper input validation vulnerability within the AMD Platform Management Framework (PMF) Driver can allow a local a...
CVE-2025-48519HIGH8.5An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local a...
CVE-2025-48512HIGH7Incorrect default permissions in the installation directory for the AMD general-purpose input/output controller (GPIO) c...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now