2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-68949MEDIUM5.3n8n is an open source workflow automation platform. From 1.36.0 to before 2.2.0, the Webhook node’s IP whitelist validat...
CVE-2025-68271CRITICAL10OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ...
CVE-2025-37166HIGH7.5A vulnerability affecting HPE Networking Instant On Access Points has been identified where a device processing a specia...
CVE-2025-37165HIGH7.5A vulnerability in the router mode configuration of HPE Instant On Access Points exposed certain network configuration d...
CVE-2025-10865HIGH7.8Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of refe...
CVE-2025-8090MEDIUM6.2Null pointer dereference in the MsgRegisterEvent() system call could allow an attacker with local access and code execut...
CVE-2025-68707HIGH8.8An authentication bypass vulnerability in the Tongyu AX1800 Wi-Fi 6 Router with firmware 1.0.0 allows unauthenticated ne...
CVE-2025-67685LOW3.8A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4,...
CVE-2025-65784MEDIUM6.5Insecure permissions in Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows authenticated attackers with low-leve...
CVE-2025-64155CRITICAL9.8An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet ...
CVE-2025-62182MEDIUM5.3Pega Customer Service Framework versions 8.7.0 through 25.1.0 are affected by a Unrestricted file upload vulnerability, ...
CVE-2025-59922HIGH7.2An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi...
CVE-2025-58693MEDIUM6.5An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiVoice 7...
CVE-2025-58411HIGH8.8Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of reso...
CVE-2025-58409LOW3.5Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to ...
CVE-2025-47855CRITICAL9.8An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 throug...
CVE-2025-46685HIGH7.8Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissio...
CVE-2025-46684MEDIUM5.5Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissio...
CVE-2025-25652HIGH7.5In Eptura Archibus 2024.03.01.109, the "Run script" and "Server File" components of the "Database Update Wizard" are vul...
CVE-2025-25249CRITICAL9.8A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS...
CVE-2025-25176CRITICAL9.1Intermediate register values of secure workloads can be exfiltrated in workloads scheduled from applications running in ...
CVE-2025-71101HIGH7.1In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: Fix out-of-bounds array a...
CVE-2025-71100HIGH7.8In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: 8192cu: fix tid out of range in rtl9...
CVE-2025-71099HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/xe/oa: Fix potential UAF in xe_oa_add_config_io...
CVE-2025-71098MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ip6_gre: make ip6gre_header() robust Over the year...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now