2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-13226HIGH8.8Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corru...
CVE-2025-36553HIGH8.8A buffer overflow vulnerability exists in the CvManager functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell...
CVE-2025-36463HIGH7.3Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter fun...
CVE-2025-36462HIGH7.3Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter fun...
CVE-2025-36461HIGH7.3Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter fun...
CVE-2025-36460HIGH7.3Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter fun...
CVE-2025-32089HIGH8.8A buffer overflow vulnerability exists in the CvManager_SBI functionality of Dell ControlVault3 prior to 5.15.14.19 and ...
CVE-2025-31649HIGH8.7A hard-coded password vulnerability exists in the ControlVault WBDI Driver functionality of Dell ControlVault3 prior to ...
CVE-2025-31361HIGH8.7A privilege escalation vulnerability exists in the ControlVault WBDI Driver WBIO_USH_ADD_RECORD functionality of Dell Co...
CVE-2025-13304HIGH8.8A security flaw has been discovered in D-Link DWR-M920, DWR-M921, DWR-M960, DWR-M961 and DIR-825M 1.01.07/1.1.47. This v...
CVE-2025-13224HIGH8.8Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corr...
CVE-2025-13223HIGH8.8Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corr...
CVE-2025-36118HIGH7.5IBM Storage Virtualize 8.4, 8.5, 8.7, and 9.1 IKEv1 implementation allows remote attackers to obtain sensitive informati...
CVE-2025-36357HIGH8IBM Planning Analytics Local 2.1.0 through 2.1.14 could allow a remote authenticated user to traverse directories on the...
CVE-2025-64756HIGH7.5Glob matches files using patterns the shell uses. Starting in version 10.2.0 and prior to versions 10.5.0 and 11.1.0, th...
CVE-2025-58407HIGH7.4Kernel or driver software installed on a Guest VM may post improper commands to the GPU Firmware to exploit a TOCTOU rac...
CVE-2025-55057HIGH8.8Multiple CWE-352 Cross-Site Request Forgery (CSRF)
CVE-2025-34323HIGH7.8Nagios Log Server versions prior to 2026R1.0.1 are vulnerable to local privilege escalation due to a combination of sudo...
CVE-2025-34322HIGH7.2Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability in the experimen...
CVE-2025-63917HIGH7.1PDFPatcher thru 1.1.3.4663 executable's XML bookmark import functionality does not restrict XML external entity (XXE) re...
CVE-2025-62519HIGH7.2phpMyFAQ is an open source FAQ web application. Prior to version 4.0.14, an authenticated SQL injection vulnerability in...
CVE-2025-58410HIGH7.5Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permissions to m...
CVE-2025-13319HIGH8.8An injection vulnerability has been discovered in the API feature in Digi On-Prem Manager, enabling an attacker with val...
CVE-2025-13290HIGH8.8A vulnerability has been found in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown ...
CVE-2025-63916HIGH8.1MyScreenTools v2.2.1.0 contains a critical OS command injection vulnerability in the GIF compression tool. The applicati...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now