2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15024 | HIGH | 8.8 | 0.2% | May 14, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Yordam Information Technology Consulting, Tra... |
| CVE-2025-15023 | HIGH | 8.8 | 0.2% | May 14, 2026 | Incorrect Authorization vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Indus... |
| CVE-2025-62628 | HIGH | 7 | 0.1% | May 14, 2026 | Unsafe OpenSSL initialization within some AMD optional tools may allow a local user-privileged attacker to inject a mali... |
| CVE-2025-15025 | HIGH | 8.8 | 0.3% | May 14, 2026 | Authorization bypass through User-Controlled key vulnerability in Yordam Information Technology Consulting, Training and... |
| CVE-2025-12008 | HIGH | 8.8 | 0.2% | May 14, 2026 | Authorization bypass through User-Controlled key vulnerability in APPYAP Technology and Information Inc. Yaay Social Med... |
| CVE-2025-68421 | HIGH | 8.7 | 0.2% | May 14, 2026 | Comarch ERP Optima client makes use of a hard-coded password for a database user. These credentials cannot be changed. I... |
| CVE-2025-68420 | HIGH | 7.5 | 0.1% | May 14, 2026 | Comarch ERP Optima client connects to a database using a high privileged account regardless of an application account to... |
| CVE-2025-14870 | HIGH | 7.5 | 0.3% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and... |
| CVE-2025-14869 | HIGH | 7.5 | 0.4% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and... |
| CVE-2025-27853 | HIGH | 7.3 | 0.3% | May 13, 2026 | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed. The WDU we... |
| CVE-2025-27850 | HIGH | 7.5 | 0.4% | May 13, 2026 | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a symlink attack. If a malicious graphics pac... |
| CVE-2025-28344 | HIGH | 7.5 | 0.3% | May 13, 2026 | striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function AuxJack. |
| CVE-2025-28343 | HIGH | 7.5 | 0.3% | May 13, 2026 | striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function ThreadReadButtons. |
| CVE-2025-11159 | HIGH | 7.2 | 0.3% | May 13, 2026 | Hitachi Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver for H2 databases which is vul... |
| CVE-2025-62627 | HIGH | 7.2 | 0.1% | May 13, 2026 | An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged ... |
| CVE-2025-62624 | HIGH | 8.8 | 0.1% | May 13, 2026 | A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege esca... |
| CVE-2025-62623 | HIGH | 8.8 | 0.1% | May 13, 2026 | A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege esca... |
| CVE-2025-61972 | HIGH | 8.5 | 0.1% | May 13, 2026 | Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to gain arbitrary System Ma... |
| CVE-2025-65088 | HIGH | 7.8 | 0.2% | May 12, 2026 | An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions... |
| CVE-2025-65087 | HIGH | 7.8 | 0.2% | May 12, 2026 | An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions... |
| CVE-2025-65086 | HIGH | 7.8 | 0.2% | May 12, 2026 | An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share version... |
| CVE-2025-53844 | HIGH | 8.8 | 0.6% | May 12, 2026 | A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 ... |
| CVE-2025-53681 | HIGH | 7.2 | 0.4% | May 12, 2026 | An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerab... |
| CVE-2025-46311 | HIGH | 7.5 | 0.2% | May 12, 2026 | An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and... |
| CVE-2025-43524 | HIGH | 8.8 | 0.1% | May 12, 2026 | An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS S... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now