2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-71217HIGH7.8An origin validation error vulnerability in the Trend Micro Apex One (mac) agent self-protection mechanism could allow a...
CVE-2025-71216HIGH7.8A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent cache mechanism could allow a local at...
CVE-2025-71215HIGH7A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent iCore service signature verification c...
CVE-2025-71214HIGH7.8An origin validation error vulnerability in the Trend Micro Apex One (mac) agent iCore service could allow a local attac...
CVE-2025-71213HIGH7.8An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on ...
CVE-2025-71212HIGH7.8A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalate privileg...
CVE-2025-13479HIGH7.5Authorization bypass through User-Controlled key vulnerability in PosCube Hardware Software and Consulting Ltd. QR Menu ...
CVE-2025-13477HIGH7.1Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerability in...
CVE-2025-32750HIGH7.5Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerabilit...
CVE-2025-11954HIGH8Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd. Co. WISECP allows Cross S...
CVE-2025-70950HIGH7.3An issue in gohttp commit 34ea51 allows attackers to execute a directory traversal via supplying a crafted request.
CVE-2025-51427HIGH7.3An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in t...
CVE-2025-15609HIGH7.5The Fortis for WooCommerce WordPress plugin before 1.3.1 may leak sensitive API keys to unauthenticated attackers, allow...
CVE-2025-57282HIGH8.8ngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection.
CVE-2025-56352HIGH7.5In tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), the broker mishandles protocol violations duri...
CVE-2025-54518HIGH7Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to...
CVE-2025-54517HIGH8.5Out of bounds write in AMD AMDGV_CMD_GET_DIAG_DATA ioctl handler could allow a local user to escalate privileges via rem...
CVE-2025-29938HIGH7.1An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to write to an arbi...
CVE-2025-29936HIGH8.4Improper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary ...
CVE-2025-29935HIGH8.4An out of bounds write within the AMD Platform Management Framework (PMF) could allow an attacker to execute arbitrary c...
CVE-2025-0028HIGH8.3An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify ...
CVE-2025-52540HIGH8.5An improper input validation vulnerability within the AMD Platform Management Framework (PMF) Driver can allow a local a...
CVE-2025-48519HIGH8.5An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local a...
CVE-2025-48512HIGH7Incorrect default permissions in the installation directory for the AMD general-purpose input/output controller (GPIO) c...
CVE-2025-15024HIGH8.8Improper Control of Generation of Code ('Code Injection') vulnerability in Yordam Information Technology Consulting, Tra...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now