2025 CVE Vulnerabilities

45,143 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-13304HIGH8.8A security flaw has been discovered in D-Link DWR-M920, DWR-M921, DWR-M960, DWR-M961 and DIR-825M 1.01.07/1.1.47. This v...
CVE-2025-13224HIGH8.8Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corr...
CVE-2025-13223HIGH8.8Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corr...
CVE-2025-36118HIGH7.5IBM Storage Virtualize 8.4, 8.5, 8.7, and 9.1 IKEv1 implementation allows remote attackers to obtain sensitive informati...
CVE-2025-36357HIGH8IBM Planning Analytics Local 2.1.0 through 2.1.14 could allow a remote authenticated user to traverse directories on the...
CVE-2025-64756HIGH7.5Glob matches files using patterns the shell uses. Starting in version 10.2.0 and prior to versions 10.5.0 and 11.1.0, th...
CVE-2025-58407HIGH7.4Kernel or driver software installed on a Guest VM may post improper commands to the GPU Firmware to exploit a TOCTOU rac...
CVE-2025-55057HIGH8.8Multiple CWE-352 Cross-Site Request Forgery (CSRF)
CVE-2025-34323HIGH7.8Nagios Log Server versions prior to 2026R1.0.1 are vulnerable to local privilege escalation due to a combination of sudo...
CVE-2025-34322HIGH7.2Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability in the experimen...
CVE-2025-63917HIGH7.1PDFPatcher thru 1.1.3.4663 executable's XML bookmark import functionality does not restrict XML external entity (XXE) re...
CVE-2025-62519HIGH7.2phpMyFAQ is an open source FAQ web application. Prior to version 4.0.14, an authenticated SQL injection vulnerability in...
CVE-2025-58410HIGH7.5Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permissions to m...
CVE-2025-13319HIGH8.8An injection vulnerability has been discovered in the API feature in Digi On-Prem Manager, enabling an attacker with val...
CVE-2025-13290HIGH8.8A vulnerability has been found in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown ...
CVE-2025-63916HIGH8.1MyScreenTools v2.2.1.0 contains a critical OS command injection vulnerability in the GIF compression tool. The applicati...
CVE-2025-63748HIGH8.8QaTraq 6.9.2 allows authenticated users to upload arbitrary files via the "Add Attachment" feature in the "Test Script" ...
CVE-2025-13289HIGH8.8A vulnerability was detected in 1000projects Design & Development of Student Database Management System 1.0. Affected is...
CVE-2025-13288HIGH8.8A security vulnerability has been detected in Tenda CH22 1.0.0.1. This impacts the function fromPptpUserSetting of the f...
CVE-2025-4321HIGH7.1In a Bluetooth device, using RS9116-WiseConnect SDK experiences a Denial of Service, if it receives malformed L2CAP pack...
CVE-2025-13287HIGH8.8A weakness has been identified in itsourcecode Online Voting System 1.0. This affects an unknown function of the file /i...
CVE-2025-13286HIGH8.8A security flaw has been discovered in itsourcecode Online Voting System 1.0. The impacted element is an unknown functio...
CVE-2025-13279HIGH8.8A vulnerability was found in code-projects Nero Social Networking Site 1.0. The affected element is an unknown function ...
CVE-2025-13278HIGH8.8A vulnerability has been found in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function ...
CVE-2025-40936HIGH7.8A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions < V29.0.258), Simcenter Fema...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now