2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-12051HIGH7.8The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-...
CVE-2025-12050HIGH7.8The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-...
CVE-2025-68947MEDIUM5.7NSecsoft 'NSecKrnl' is a Windows driver that allows a local, authenticated attacker to terminate processes owned by othe...
CVE-2025-68658MEDIUM4.8Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram...
CVE-2025-37186HIGH7.8A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking Virtual Intranet Access (VIA)...
CVE-2025-15056MEDIUM6.1A lack of data validation vulnerability in the HTML export feature in Quill in allows Cross-Site Scripting (XSS). This ...
CVE-2025-68931HIGH7.5Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, AES/CBC/PKCS5Padding...
CVE-2025-68925MEDIUM5.3Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the code doesn't val...
CVE-2025-68704HIGH7.5Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses java.uti...
CVE-2025-68703HIGH7.5Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the salt is derived ...
CVE-2025-68702HIGH7.5Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses padLeft(...
CVE-2025-68701HIGH7.5Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses determin...
CVE-2025-68698HIGH7.5Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses PKCS1Enc...
CVE-2025-37179MEDIUM5.3Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data ...
CVE-2025-37178HIGH7.5Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data ...
CVE-2025-37177MEDIUM6.5An arbitrary file deletion vulnerability has been identified in the command-line interface of mobility conductors runnin...
CVE-2025-37176HIGH7.2A command injection vulnerability in AOS-8 allows an authenticated privileged user to alter a package header to inject s...
CVE-2025-37175HIGH7.2Arbitrary file upload vulnerability exists in the web-based management interface of mobility conductors running either A...
CVE-2025-37174HIGH7.2Authenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors run...
CVE-2025-37173HIGH7.2An improper input handling vulnerability exists in the web-based management interface of mobility conductors running eit...
CVE-2025-37172HIGH7.2Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors runni...
CVE-2025-37171HIGH7.2Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors runni...
CVE-2025-37170HIGH7.2Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors runni...
CVE-2025-37169HIGH7.2A stack overflow vulnerability exists in the AOS-10 web-based management interface of a Mobility Gateway. Successful exp...
CVE-2025-37168CRITICAL9.1Arbitrary file deletion vulnerability have been identified in a system function of mobility conductors running AOS-8 ope...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now