2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-15024HIGH8.8Improper Control of Generation of Code ('Code Injection') vulnerability in Yordam Information Technology Consulting, Tra...
CVE-2025-15023HIGH8.8Incorrect Authorization vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Indus...
CVE-2025-62628HIGH7Unsafe OpenSSL initialization within some AMD optional tools may allow a local user-privileged attacker to inject a mali...
CVE-2025-15025HIGH8.8Authorization bypass through User-Controlled key vulnerability in Yordam Information Technology Consulting, Training and...
CVE-2025-12008HIGH8.8Authorization bypass through User-Controlled key vulnerability in APPYAP Technology and Information Inc. Yaay Social Med...
CVE-2025-68421HIGH8.7Comarch ERP Optima client makes use of a hard-coded password for a database user. These credentials cannot be changed. I...
CVE-2025-68420HIGH7.5Comarch ERP Optima client connects to a database using a high privileged account regardless of an application account to...
CVE-2025-14870HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and...
CVE-2025-14869HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and...
CVE-2025-27853HIGH7.3The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed. The WDU we...
CVE-2025-27850HIGH7.5The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a symlink attack. If a malicious graphics pac...
CVE-2025-28344HIGH7.5striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function AuxJack.
CVE-2025-28343HIGH7.5striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function ThreadReadButtons.
CVE-2025-11159HIGH7.2Hitachi Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver for H2 databases which is vul...
CVE-2025-62627HIGH7.2An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged ...
CVE-2025-62624HIGH8.8A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege esca...
CVE-2025-62623HIGH8.8A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege esca...
CVE-2025-61972HIGH8.5Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to gain arbitrary System Ma...
CVE-2025-65088HIGH7.8An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions...
CVE-2025-65087HIGH7.8An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions...
CVE-2025-65086HIGH7.8An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share version...
CVE-2025-53844HIGH8.8A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 ...
CVE-2025-53681HIGH7.2An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerab...
CVE-2025-46311HIGH7.5An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and...
CVE-2025-43524HIGH8.8An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS S...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now