2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-65018HIGH7.1LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ...
CVE-2025-64720HIGH7.1LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ...
CVE-2025-62155HIGH8.5New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to versio...
CVE-2025-54563HIGH7.5An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.1...
CVE-2025-54338HIGH7.5An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.1...
CVE-2025-52538HIGH8Improper input validation within the XOCL driver may allow a local attacker to generate an integer overflow condition, p...
CVE-2025-48510HIGH7.1Improper return value within AMD uProf can allow a local attacker to bypass KSLR, potentially resulting in loss of confi...
CVE-2025-36150HIGH7.5IBM Concert 1.0.0 through 2.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decry...
CVE-2025-0003HIGH7.3Inadequate lock protection within Xilinx Run time may allow a local attacker to trigger a Use-After-Free condition poten...
CVE-2025-56400HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, a...
CVE-2025-52539HIGH7.3A buffer overflow with Xilinx Run Time Environment may allow a local attacker to read or corrupt data from the advanced ...
CVE-2025-0005HIGH7.3Improper input validation within the XOCL driver may allow a local attacker to generate an integer overflow condition, p...
CVE-2025-13609HIGH8.2A vulnerability has been identified in keylime where an attacker can exploit this flaw by registering a new agent using ...
CVE-2025-63434HIGH8.8The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downl...
CVE-2025-60915HIGH8.1An issue in the size query parameter (/views/file.py) of Austrian Archaeological Institute Openatlas before v8.12.0 allo...
CVE-2025-60638HIGH7.5An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST ...
CVE-2025-56401HIGH7.6ZIRA Group WBRM 7.0 is vulnerable to SQL Injection in referenceLookupsByTableNameAndColumnName.
CVE-2025-44018HIGH8.3A firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4.7.0. A specially craft...
CVE-2025-40213HIGH7.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: fix crash in set_mesh_sync and set...
CVE-2025-10555HIGH8.7A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in DELMIA Service Process Engineer ...
CVE-2025-12970HIGH8.8The extract_name function in Fluent Bit in_docker input plugin copies container names into a fixed size stack buffer wit...
CVE-2025-11921HIGH8.5iStats contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via c...
CVE-2025-65998HIGH7.5Apache Syncope can be configured to store the user password values in the internal database with AES encryption, though ...
CVE-2025-65495HIGH7.5Integer signedness error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers t...
CVE-2025-65494HIGH7.5NULL pointer dereference in get_san_or_cn_from_cert() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attacker...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now