2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-64501HIGH7.6ProsemirrorToHtml is a JSON converter which takes ProseMirror-compatible JSON and outputs HTML. In versions 0.2.0 and be...
CVE-2025-64484HIGH8.5OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrat...
CVE-2025-64183HIGH7.5OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2025-64182HIGH7.8OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2025-64181HIGH7.5OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2025-63149HIGH7.5Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the urls parameter of the get_parentControl_list...
CVE-2025-12727HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.137 allowed a remote attacker to potentially exp...
CVE-2025-12726HIGH7.5Inappropriate implementation in Views in Google Chrome on Windows prior to 142.0.7444.137 allowed a remote attacker who ...
CVE-2025-12725HIGH8.8Out of bounds read in WebGPU in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker to perform an...
CVE-2025-12438HIGH8.8Use after free in Ozone in Google Chrome on Linux and ChromeOS prior to 142.0.7444.59 allowed a remote attacker to poten...
CVE-2025-12437HIGH7.5Use after free in PageInfo in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to eng...
CVE-2025-12432HIGH8.8Race in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via ...
CVE-2025-12430HIGH7.5Object lifecycle issue in Media in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing...
CVE-2025-12429HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform arbitrar...
CVE-2025-12428HIGH8.8Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform arbitrary read/write v...
CVE-2025-63288HIGH7.5In Open5GS 2.7.6, AMF crashes when receiving an abnormal NGSetupRequest message, resulting in denial of service.
CVE-2025-47286HIGH7.2Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, an administrator can, by ...
CVE-2025-43723HIGH7.5Dell PowerScale OneFS, versions prior to 9.10.1.3 and versions 9.11.0.0 through 9.12.0.0, contains a use of a broken or ...
CVE-2025-12967HIGH8.6An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low pr...
CVE-2025-63835HIGH8.8A stack-based buffer overflow vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in...
CVE-2025-63497HIGH7.1The patient prescription viewing functionality in his_doc_view_single_patient.php of rickxy Hospital Management System v...
CVE-2025-63457HIGH7.5Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the wanMTU parameter in the sub_4F55C function. Th...
CVE-2025-63456HIGH7.5Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the SetSysTimeCfg function. ...
CVE-2025-63455HIGH7.5Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGus...
CVE-2025-63147HIGH7.5Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the deviceId parameter of the saveParentControlI...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now