2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-64522HIGH7.6Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where ...
CVE-2025-64519HIGH8.8TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In versions up to and including ...
CVE-2025-63678HIGH7.2An authenticated arbitrary file upload vulnerability in the /uploads/ endpoint of CMS Made Simple Foundation File Manage...
CVE-2025-11578HIGH7.2A privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise...
CVE-2025-64518HIGH7.5The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, valida...
CVE-2025-64512HIGH7.8Pdfminer.six is a community maintained fork of the original PDFMiner, a tool for extracting information from PDF documen...
CVE-2025-64509HIGH7.5Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.6, a specially crafted Brotli-compressed envelope...
CVE-2025-64508HIGH7.5Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.5, brotli "bombs" (highly compressed brotli strea...
CVE-2025-64507HIGH7.8Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incu...
CVE-2025-64501HIGH7.6ProsemirrorToHtml is a JSON converter which takes ProseMirror-compatible JSON and outputs HTML. In versions 0.2.0 and be...
CVE-2025-64484HIGH8.5OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrat...
CVE-2025-64183HIGH7.5OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2025-64182HIGH7.8OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2025-64181HIGH7.5OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2025-63149HIGH7.5Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the urls parameter of the get_parentControl_list...
CVE-2025-12727HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.137 allowed a remote attacker to potentially exp...
CVE-2025-12726HIGH7.5Inappropriate implementation in Views in Google Chrome on Windows prior to 142.0.7444.137 allowed a remote attacker who ...
CVE-2025-12725HIGH8.8Out of bounds read in WebGPU in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker to perform an...
CVE-2025-12438HIGH8.8Use after free in Ozone in Google Chrome on Linux and ChromeOS prior to 142.0.7444.59 allowed a remote attacker to poten...
CVE-2025-12437HIGH7.5Use after free in PageInfo in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to eng...
CVE-2025-12432HIGH8.8Race in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via ...
CVE-2025-12430HIGH7.5Object lifecycle issue in Media in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing...
CVE-2025-12429HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform arbitrar...
CVE-2025-12428HIGH8.8Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform arbitrary read/write v...
CVE-2025-63288HIGH7.5In Open5GS 2.7.6, AMF crashes when receiving an abnormal NGSetupRequest message, resulting in denial of service.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now