2025 CVE Vulnerabilities

45,144 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-40183HIGH7.5In the Linux kernel, the following vulnerability has been resolved: bpf: Fix metadata_dst leak __bpf_redirect_neigh_v{4...
CVE-2025-40182HIGH7.8In the Linux kernel, the following vulnerability has been resolved: crypto: skcipher - Fix reqsize handling Commit afd...
CVE-2025-46608HIGH7.2Dell Data Lakehouse, versions prior to 1.6.0.0, contain(s) an Improper Access Control vulnerability. A high privileged a...
CVE-2025-13063HIGH7.3A flaw has been found in DinukaNavaratna Dee Store 1.0. Affected is an unknown function. Executing manipulation can lead...
CVE-2025-13061HIGH8.8A vulnerability was detected in itsourcecode Online Voting System 1.0. This impacts an unknown function of the file /ind...
CVE-2025-8485HIGH7.3An improper permissions vulnerability was reported in Lenovo App Store that could allow a local authenticated user to ex...
CVE-2025-46428HIGH8.8Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used...
CVE-2025-46427HIGH8.8Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used ...
CVE-2025-12048HIGH7.7An arbitrary file upload vulnerability was reported in the Lenovo Scanner Pro client during an internal security assessm...
CVE-2025-10495HIGH7.7A potential vulnerability was reported in the Lenovo PC Manager, Lenovo App Store, Lenovo Browser, and Lenovo Legion Zon...
CVE-2025-64099HIGH8.1Open Access Management (OpenAM) is an access management solution. In versions prior to 16.0.0, if the "claims_parameter_...
CVE-2025-63929HIGH7.5A null pointer dereference vulnerability exists in airpig2011 IEC104 thru Commit be6d841 (2019-07-08). When multiple thr...
CVE-2025-63679HIGH7.5free5gc v4.1.0 and before is vulnerable to Buffer Overflow. When AMF receives an UplinkRANConfigurationTransfer NGAP mes...
CVE-2025-61667HIGH7The Datadog Agent collects events and metrics from hosts and sends them to Datadog. A vulnerability within the Datadog L...
CVE-2025-57310HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability in Salmen2/Simple-Faucet-Script v1.07 via crafted POST request to admi...
CVE-2025-65002HIGH7.5Fujitsu / Fsas Technologies iRMC S6 on M5 before 1.37S mishandles Redfish/WebUI access if the length of a username is ex...
CVE-2025-65001HIGH8.2Fujitsu fbiosdrv.sys before 2.5.0.0 allows an attacker to potentially affect system confidentiality, integrity, and avai...
CVE-2025-63811HIGH7.5An issue was discovered in dvsekhvalnov jose2go 1.5.0 thru 1.7.0 allowing an attacker to cause a Denial-of-Service (DoS)...
CVE-2025-59088HIGH8.6If kdcproxy receives a request for a realm which does not have server addresses defined in its configuration, by default...
CVE-2025-2843HIGH8.8A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment...
CVE-2025-13042HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.166 allowed a remote attacker to potentially exp...
CVE-2025-11797HIGH7.8A maliciously crafted DWG file, when parsed through Autodesk 3ds Max, can force a Use-After-Free vulnerability. A malici...
CVE-2025-11795HIGH7.8A maliciously crafted JPG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A ...
CVE-2025-64293HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Golemiq 0 Day Anal...
CVE-2025-11700HIGH7.5N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now